mirror of
https://github.com/alsk1992/CloddsBot.git
synced 2026-10-02 02:54:40 +08:00
fix: restore security CI
This commit is contained in:
@@ -18,10 +18,10 @@ jobs:
|
||||
cache: npm
|
||||
- name: Install
|
||||
run: npm ci
|
||||
- name: Security audit
|
||||
run: npx --yes audit-ci --config audit-ci.jsonc --high --production
|
||||
- name: Typecheck, test, build
|
||||
run: npm run ci
|
||||
- name: Security audit
|
||||
run: npx --yes audit-ci --config audit-ci.jsonc --high --production
|
||||
|
||||
security:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
+7
-14
@@ -3,9 +3,8 @@
|
||||
//
|
||||
// Every advisory below is transitive through the Solana/crypto SDK ecosystem's own
|
||||
// pinned old dependencies (@project-serum/anchor, @coral-xyz/anchor, @drift-labs/sdk,
|
||||
// and friends depend on old @solana/web3.js/protobufjs/uuid/@grpc-js internally) or,
|
||||
// for sharp, an inherited native-library CVE with no upstream fix published yet even
|
||||
// on the latest sharp release. None of these have a fix that doesn't mean either
|
||||
// and friends depend on old @solana/web3.js/protobufjs/uuid/@grpc-js internally).
|
||||
// None of these have a fix that doesn't mean either
|
||||
// downgrading a currently-working trading integration or forcing a major bump whose
|
||||
// breaking changes haven't been vetted (e.g. @drift-labs/sdk's suggested fix requires
|
||||
// Node 24, a separate decision from a routine audit pass).
|
||||
@@ -38,10 +37,6 @@
|
||||
"GHSA-wcpc-wj8m-hjx6",
|
||||
"GHSA-f38q-mgvj-vph7",
|
||||
|
||||
// sharp — inherited libvips CVEs. Already on the latest sharp (0.35.4, bumped this
|
||||
// same pass); no newer release exists yet that fixes the underlying libvips CVEs.
|
||||
"GHSA-f88m-g3jw-g9cj",
|
||||
|
||||
// uuid — v3/v5/v6 buffer-bounds check (the v4 generator is unaffected). Verified
|
||||
// node-cron's own source only calls uuid.v4() (scheduled-task.js, storage.js).
|
||||
// The other path, @wormhole-foundation/sdk-solana's pinned rpc-websockets, has no
|
||||
@@ -50,12 +45,10 @@
|
||||
// a closer look, not as verified-safe the way node-cron's path is.
|
||||
"GHSA-w5hq-g745-h8pq",
|
||||
|
||||
// extract-zip — symlink path-traversal, via puppeteer>@puppeteer/browsers. No
|
||||
// patched version published yet. extract-zip is only used by @puppeteer/browsers'
|
||||
// own setup step to unpack the pinned, official Chromium build it downloads from
|
||||
// Google's CDN — CloddsBot never feeds it a user-controlled or otherwise untrusted
|
||||
// zip (the actual PDF-export feature in src/extensions/open-prose only drives an
|
||||
// already-launched browser; it doesn't touch this download/extract path).
|
||||
"GHSA-jmr9-qjv8-65gv"
|
||||
// stream-json — quadratic behavior is confined to the pick/ignore/filter/replace
|
||||
// helpers. The only production consumer is jayson, which imports StreamValues and
|
||||
// Verifier instead. jayson 4.3 pins stream-json 1.x and is incompatible with the
|
||||
// patched 3.x module paths, so forcing the major would break Solana RPC parsing.
|
||||
"GHSA-528h-pc64-c93x"
|
||||
]
|
||||
}
|
||||
|
||||
Generated
+297
-724
File diff suppressed because it is too large
Load Diff
+5
-3
@@ -138,7 +138,7 @@
|
||||
"json5": "^2.2.3",
|
||||
"mammoth": "^1.11.0",
|
||||
"node-cron": "^3.0.3",
|
||||
"nodemailer": "^9.0.6",
|
||||
"nodemailer": "^9.1.1",
|
||||
"pg": "^8.17.2",
|
||||
"pino": "^8.18.0",
|
||||
"pino-pretty": "^10.3.1",
|
||||
@@ -165,7 +165,9 @@
|
||||
"@cosmjs/stargate": "^0.38.1",
|
||||
"@cosmjs/tendermint-rpc": "^0.38.1",
|
||||
"@cosmjs/cosmwasm-stargate": "^0.38.1",
|
||||
"@solana/kit": "^5.0.0"
|
||||
"@solana/kit": "^5.0.0",
|
||||
"sharp": "$sharp",
|
||||
"toml": "^4.2.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/express": "^4.17.21",
|
||||
@@ -174,7 +176,7 @@
|
||||
"@types/nodemailer": "^6.4.22",
|
||||
"@types/sql.js": "^1.4.9",
|
||||
"@types/ws": "^8.5.10",
|
||||
"puppeteer": "^24.37.5",
|
||||
"puppeteer": "^25.10.0",
|
||||
"tsx": "^4.7.0",
|
||||
"typescript": "^5.3.3"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user