Skip to content

fix: refresh audited transitive dependency locks - #452

Draft
TheAmericanMaker wants to merge 1 commit into
mainfrom
paperclip/HUGA-17-restore-ci-audit-gate-after-new-brace-expansion-and-undici-advisories
Draft

TheAmericanMaker wants to merge 1 commit into
mainfrom
paperclip/HUGA-17-restore-ci-audit-gate-after-new-brace-expansion-and-undici-advisories

Conversation

@TheAmericanMaker

Copy link
Copy Markdown
Member

What changed

Updated only package-lock.json to resolve brace-expansion 5.0.12 and undici 8.11.2. The Pi peer remains at 0.85.1; no package manifest or runtime code changed.

The prior lock resolved vulnerable brace-expansion 5.0.9 and undici 8.10.0, which caused the production audit gate to fail before build and tests. This unblocks the audit gate affecting PRs #450 and #451. Tracks Paperclip ticket HUGA-17. There is no corresponding GitHub issue to close.

Verification

  • Before the change, npm audit --omit=dev --audit-level=high exited 1 with high-severity advisories for both packages.
  • After the change, npm audit --omit=dev --audit-level=high exited 0:
    found 0 vulnerabilities
    
  • npm ci exited 0: added 137 packages, and audited 138 packages in 2s and found 0 vulnerabilities.
  • npm run build exited 0 (tsc).
  • npm test exited 0 after the build completed:
    # tests 1374
    # pass 1374
    # fail 0
    # cancelled 0
    # skipped 0
    # todo 0
    
  • The first npm test run overlapped npm run build and failed 32 tests while dist/mcp-server/server.js was unavailable. The sequential rerun passed.

Windows was not run locally on this Linux host; CI test-windows will verify it. CI test (22) and test (24) will verify the audit gate and tests on both supported Node versions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant