Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,13 @@ All notable changes to this project are documented in this file.

## [Unreleased]

### Fixed — production `npm audit --omit=dev` (GHSA-6qxp-vccf-f47h, GHSA-jqcg-44mw-7w3h)

- Direct `@modelcontextprotocol/sdk` (root and `packages/efficiency-agent`) moved from `^1.30.0` to `^1.32.1`. The advisory range was `<1.31.0` (OAuth client could send credentials to an authorization server chosen by the MCP server).
- `overrides.proxy-addr` is `^2.0.8`. express still declares `^2.0.7`, which resolved to the vulnerable `2.0.7` (IPv4-mapped IPv6 trust spoofing).

## [Unreleased]

### Fixed — 第 0 步性能与健壮性(迁移 Rust 前的架构债清偿,复审登记项全闭环)

- **file 传输读路径共享缓存(P2-8)**:`GraphifyFileClient.peekStore()` 静态共享读入口(走进程内 `graphifyFileStoreCache`,stat 校验+delta 已应用,不开句柄不写);`graphStoreNeedsIndexing` 与 `readFileGraphStore`/`resolveGraphStoreAfterIndex` 不再各自 readFileSync+JSON.parse 整个 9.5MB store——每 preview 省 2 次全量读+解析。消费方 mutation 全审计(全只读),peek 结果仍做浅拷贝防御未来调用方。
Expand Down
22 changes: 13 additions & 9 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 4 additions & 3 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -166,7 +166,7 @@
"vitest": "^3.2.6"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.0",
"@modelcontextprotocol/sdk": "^1.32.1",
"ajv": "^8.17.1",
"ajv-formats": "^3.0.1",
"gpt-tokenizer": "^3.4.0",
Expand All @@ -185,9 +185,10 @@
"body-parser": "^2.3.0",
"fast-uri": "^3.1.7",
"ip-address": "^10.7.2",
"qs": "^6.16.0"
"qs": "^6.16.0",
"proxy-addr": "^2.0.8"
},
"overridesComment": "Pinned past advisories in transitive deps. Six were non-breaking and lifted npm audit to zero: hono (cross-request data disclosure / ReDoS / SSRF-adjacent parser issues), @hono/node-server (Windows path traversal via encoded backslash), body-parser (DoS when an invalid limit silently disables size enforcement), fast-uri (host confusion and SSRF), ip-address (SSRF via octet and IPv6 misclassification), qs (array-limit bypass, DoS). The only remaining route was @huggingface/transformers 3.x -> 4.3.0, which pulls sharp 0.35.5 and clears the libvips/libheif CVEs; verified against the exact API surface used in src/learning/embeddings.ts (pipeline, env.cacheDir, env.remoteHost).",
"overridesComment": "Pinned past advisories in transitive deps. Six were non-breaking and lifted an earlier npm audit to zero: hono (cross-request data disclosure / ReDoS / SSRF-adjacent parser issues), @hono/node-server (Windows path traversal via encoded backslash), body-parser (DoS when an invalid limit silently disables size enforcement), fast-uri (host confusion and SSRF), ip-address (SSRF via octet and IPv6 misclassification), qs (array-limit bypass, DoS). @huggingface/transformers 4.3.0 pulls sharp 0.35.5 and clears the libvips/libheif CVEs; verified against the exact API surface used in src/learning/embeddings.ts (pipeline, env.cacheDir, env.remoteHost). proxy-addr ^2.0.8 clears GHSA-jqcg-44mw-7w3h (IPv4-mapped IPv6 trust spoofing) inside express, which still accepts ^2.0.7. @modelcontextprotocol/sdk is a direct dependency pinned to ^1.32.1 (advisory range was <1.31.0, GHSA-6qxp-vccf-f47h).",
"disclosure": {
"cloud": true,
"network": [
Expand Down
2 changes: 1 addition & 1 deletion packages/efficiency-agent/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
"sbom": "node scripts/supply-chain.mjs"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.30.0"
"@modelcontextprotocol/sdk": "^1.32.1"
},
"devDependencies": {
"@types/node": "^25.9.1",
Expand Down
15 changes: 15 additions & 0 deletions tests/security-audit-script.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,21 @@ describe("security-audit script", () => {
}
});

it("pins the production advisories that npm audit --omit=dev currently reports", () => {
const pkg = JSON.parse(readFileSync(join(process.cwd(), "package.json"), "utf8")) as {
dependencies: Record<string, string>;
overrides: Record<string, string>;
};
const agent = JSON.parse(
readFileSync(join(process.cwd(), "packages/efficiency-agent/package.json"), "utf8")
) as { dependencies: Record<string, string> };
// GHSA-6qxp-vccf-f47h: @modelcontextprotocol/sdk <1.31.0
expect(pkg.dependencies["@modelcontextprotocol/sdk"]).toBe("^1.32.1");
expect(agent.dependencies["@modelcontextprotocol/sdk"]).toBe("^1.32.1");
// GHSA-jqcg-44mw-7w3h: proxy-addr <2.0.8, still allowed by express's ^2.0.7
expect(pkg.overrides["proxy-addr"]).toBe("^2.0.8");
});

it("imports join from node:path so the scheduled audit can start", () => {
const src = readFileSync(join(process.cwd(), "scripts/security-audit.cjs"), "utf8");
expect(src).toMatch(/require\(["']node:path["']\)/);
Expand Down
Loading