Skip to content

fix(deps): resolve high-severity advisories blocking CI - #295

Merged
StuMason merged 1 commit into
mainfrom
fix/audit-high-vulns
Jul 29, 2026
Merged

StuMason merged 1 commit into
mainfrom
fix/audit-high-vulns

Conversation

@StuMason

Copy link
Copy Markdown
Owner

Problem

npm audit --audit-level=high is a required CI step, and it currently fails on main: 8 advisories, 4 of them high.

This is not caused by any change. main last ran green on 16 Jul at e8dfb4b; the advisories were published after that, so main would fail today if re-run. The practical effect is that every open PR is blocked on a red check that has nothing to do with its own diff, which is what PR #294 has been sitting on.

Verified by running the exact CI gate against main's own lockfile in isolation: exit 1, 8 advisories.

Fix

npm audit fix, which resolves all four highs using transitive patch/minor bumps only.

Package From To Severity
brace-expansion 5.0.6 5.0.8 high (DoS via exponential expansion)
fast-uri 4.0.0 4.1.1 high (host confusion)
js-yaml 4.2.0 4.3.0 high (quadratic CPU via merge keys)
linkify-it 5.0.1 5.0.2 high (quadratic DoS)
@hono/node-server 2.0.5 2.0.12 moderate (memory-leak DoS)
hono 4.12.25 4.12.32 moderate
@babel/core 7.29.0 7.29.7 low

Result: 8 advisories to 1 low, comfortably under the gate.

The one remaining low is body-parser, which has no fix available that does not require a breaking change. It is below the --audit-level=high threshold so it does not gate CI.

Scope

package-lock.json only. package.json is untouched, and no direct dependency changed, so there is no version-range or API surface impact. Every bump is transitive and patch or minor.

Testing

Ran all six CI steps locally against a clean export of the committed tree:

  • npm audit --audit-level=high — pass (was failing)
  • npx prettier --check . — pass
  • npm run lint — pass
  • npm run check:spec-drift — pass
  • npm run build — pass
  • npm run test:coverage — pass, 424/424 tests, 98.2% statements / 99.53% functions

Merge order

This should go in first. Once it lands, #294 needs a rebase to pick it up and should then go green and auto-merge.

npm audit --audit-level=high (the CI gate) fails on main: 8 advisories,
4 of them high. Main last ran green on 16 Jul; the advisories were
published after that, so the break is time-based rather than caused by
any change. It blocks every open PR.

npm audit fix resolves all four highs with transitive patch/minor bumps
only. package.json is untouched and no direct dependency changes, so
there is no version-range or API surface impact.

  brace-expansion   5.0.6  -> 5.0.8   (high, DoS)
  fast-uri          4.0.0  -> 4.1.1   (high, host confusion)
  js-yaml           4.2.0  -> 4.3.0   (high, quadratic CPU)
  linkify-it        5.0.1  -> 5.0.2   (high, quadratic DoS)
  @hono/node-server 2.0.5  -> 2.0.12  (moderate, memory-leak DoS)
  hono              4.12.25 -> 4.12.32 (moderate)
  @babel/core       7.29.0 -> 7.29.7  (low)

Takes the audit from 8 advisories to 1 low, which is below the gate.
The remaining low is body-parser, which has no fix that does not require
a breaking change.
@codecov

codecov Bot commented Jul 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.61%. Comparing base (e8dfb4b) to head (04ae327).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #295   +/-   ##
=======================================
  Coverage   91.61%   91.61%           
=======================================
  Files           3        3           
  Lines         620      620           
  Branches      163      163           
=======================================
  Hits          568      568           
  Misses          6        6           
  Partials       46       46           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@claude

claude Bot commented Jul 29, 2026

Copy link
Copy Markdown

Code Review

Summary: This PR is a pure package-lock.json update — package.json is untouched. Only transitive dependency versions changed.

Security

The motivation is sound. The four high-severity advisories fixed here are real CVEs:

  • brace-expansion 5.0.6 → 5.0.8 — ReDoS via exponential brace expansion (high)
  • fast-uri 4.0.0 → 4.1.1 — Host-header confusion (high)
  • js-yaml 4.2.0 → 4.3.0 — Quadratic CPU via YAML merge keys (high)
  • linkify-it 5.0.1 → 5.0.2 — Quadratic DoS (high)

All four are addressed by patch/minor bumps, which is the correct and minimal approach.

The remaining low-severity body-parser advisory is noted as having no fix without a breaking change. That's a reasonable call — it falls below the --audit-level=high CI gate, so it doesn't block anything.

Scope

Verified: only package-lock.json changed. No package.json ranges were altered, so there's no API surface change or risk of unexpected major-version jumps. The lockfile is the right place to pin transitive fixes like these.

The brace-expansion node engine floor moved from node: "18 || 20 || >=22" to node: "20 || >=22" — worth noting if Node 18 support is a concern, but since @hono/node-server already requires >=20, the project's effective floor is already Node 20+.

Testing

The PR description reports 424/424 tests passing with 98.2% statement coverage after this change. That's consistent with what we'd expect — no source files changed, so test outcomes shouldn't change.

Verdict

Approve. This is a well-scoped, minimal fix for a legitimate CI blocker. The changes are entirely mechanical (lockfile-only, no code), the approach (npm audit fix) is correct, and the description is thorough. No concerns.

@StuMason
StuMason merged commit a0bc71d into main Jul 29, 2026
8 checks passed
@StuMason
StuMason deleted the fix/audit-high-vulns branch July 29, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant