Skip to content

fix(deps): remediate CRITICAL/high audit advisories (no breaking changes) - #54

Merged
EmeditWeb merged 2 commits into
mainfrom
fix/app-deps-security-safe
Sep 29, 2026
Merged

EmeditWeb merged 2 commits into
mainfrom
fix/app-deps-security-safe

Conversation

@EmeditWeb

Copy link
Copy Markdown
Member

What

Remediates the dependency vulnerabilities that are fixable without any breaking (semver-major) change, applied via a non-forced npm audit fix using the repo's own --legacy-peer-deps resolution mode (matching CI).

Fixed — both CRITICALs + highs

  • CRITICAL shell-quote — quote() does not escape newlines in object .op values (command-injection class)
  • CRITICAL tar — PAX size-override applied to intermediary GNU long-name/long-link headers
  • 8 high + 2 low transitive advisories (axios, form-data, undici, ws, nanoid, js-yaml, @xmldom/xmldom, browserslist, …)

All fixes are same-major version bumps. Only package-lock.json changed.

Audit delta

critical high moderate low total
before 2 18 19 2 41
after 0 10 17 0 27

Intentionally deferred (not in this PR)

The residual 27 are the expo 54→57 / metro major-upgrade cluster and a few advisories whose only npm-proposed "fix" resolves to a bogus ancient version (e.g. @react-navigation/*). These require a real framework migration, not a lockfile bump, and belong in a dedicated PR — especially given this repo's development pause (#51).

Verification

  • npx expo export --platform web — passes (exit 0, bundles + dist/ produced). This is the CI gate and exercises the exact bundler/build path where the fixed deps (shell-quote, tar, metro tooling) live.

Test plan

  • npm ci --legacy-peer-deps clean
  • npm audit fix (non-forced) applies only same-major fixes
  • npx expo export --platform web succeeds
  • CI green on this PR

🤖 Generated with Claude Code

EmeditWeb and others added 2 commits September 14, 2026 10:26
…changes

Non-forced `npm audit fix` (legacy-peer-deps, matching CI resolution). Clears both CRITICAL advisories — shell-quote (quote() newline-escape) and tar (PAX size-override) — plus 8 high and 2 low transitive advisories, all via same-major bumps.

No semver-major changes were applied: the expo 54->57 / metro cluster and the bogus-resolution react-navigation moderates are intentionally left for a dedicated migration PR.

Audit: 41 -> 27 total (critical 2->0, high 18->10, low 2->0). Verified: `npx expo export --platform web` succeeds (the CI gate). Only package-lock.json changed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@EmeditWeb
EmeditWeb merged commit 2dbde84 into main Sep 29, 2026
4 checks passed
@EmeditWeb
EmeditWeb deleted the fix/app-deps-security-safe branch September 29, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant