fix(deps): resolve high-severity advisories blocking CI - #295
Conversation
npm audit --audit-level=high (the CI gate) fails on main: 8 advisories, 4 of them high. Main last ran green on 16 Jul; the advisories were published after that, so the break is time-based rather than caused by any change. It blocks every open PR. npm audit fix resolves all four highs with transitive patch/minor bumps only. package.json is untouched and no direct dependency changes, so there is no version-range or API surface impact. brace-expansion 5.0.6 -> 5.0.8 (high, DoS) fast-uri 4.0.0 -> 4.1.1 (high, host confusion) js-yaml 4.2.0 -> 4.3.0 (high, quadratic CPU) linkify-it 5.0.1 -> 5.0.2 (high, quadratic DoS) @hono/node-server 2.0.5 -> 2.0.12 (moderate, memory-leak DoS) hono 4.12.25 -> 4.12.32 (moderate) @babel/core 7.29.0 -> 7.29.7 (low) Takes the audit from 8 advisories to 1 low, which is below the gate. The remaining low is body-parser, which has no fix that does not require a breaking change.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #295 +/- ##
=======================================
Coverage 91.61% 91.61%
=======================================
Files 3 3
Lines 620 620
Branches 163 163
=======================================
Hits 568 568
Misses 6 6
Partials 46 46 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Code ReviewSummary: This PR is a pure SecurityThe motivation is sound. The four high-severity advisories fixed here are real CVEs:
All four are addressed by patch/minor bumps, which is the correct and minimal approach. The remaining low-severity ScopeVerified: only The TestingThe PR description reports 424/424 tests passing with 98.2% statement coverage after this change. That's consistent with what we'd expect — no source files changed, so test outcomes shouldn't change. VerdictApprove. This is a well-scoped, minimal fix for a legitimate CI blocker. The changes are entirely mechanical (lockfile-only, no code), the approach ( |
Problem
npm audit --audit-level=highis a required CI step, and it currently fails onmain: 8 advisories, 4 of them high.This is not caused by any change.
mainlast ran green on 16 Jul ate8dfb4b; the advisories were published after that, somainwould fail today if re-run. The practical effect is that every open PR is blocked on a red check that has nothing to do with its own diff, which is what PR #294 has been sitting on.Verified by running the exact CI gate against
main's own lockfile in isolation: exit 1, 8 advisories.Fix
npm audit fix, which resolves all four highs using transitive patch/minor bumps only.brace-expansionfast-urijs-yamllinkify-it@hono/node-serverhono@babel/coreResult: 8 advisories to 1 low, comfortably under the gate.
The one remaining low is
body-parser, which has no fix available that does not require a breaking change. It is below the--audit-level=highthreshold so it does not gate CI.Scope
package-lock.jsononly.package.jsonis untouched, and no direct dependency changed, so there is no version-range or API surface impact. Every bump is transitive and patch or minor.Testing
Ran all six CI steps locally against a clean export of the committed tree:
npm audit --audit-level=high— pass (was failing)npx prettier --check .— passnpm run lint— passnpm run check:spec-drift— passnpm run build— passnpm run test:coverage— pass, 424/424 tests, 98.2% statements / 99.53% functionsMerge order
This should go in first. Once it lands, #294 needs a rebase to pick it up and should then go green and auto-merge.