fix: restore security CI

This commit is contained in:
AL
2026-09-10 18:49:14 +01:00
parent 07d00a022e
commit 491cbaec9f
4 changed files with 311 additions and 743 deletions
+2 -2
View File
@@ -18,10 +18,10 @@ jobs:
cache: npm
- name: Install
run: npm ci
- name: Security audit
run: npx --yes audit-ci --config audit-ci.jsonc --high --production
- name: Typecheck, test, build
run: npm run ci
- name: Security audit
run: npx --yes audit-ci --config audit-ci.jsonc --high --production
security:
runs-on: ubuntu-latest
+7 -14
View File
@@ -3,9 +3,8 @@
//
// Every advisory below is transitive through the Solana/crypto SDK ecosystem's own
// pinned old dependencies (@project-serum/anchor, @coral-xyz/anchor, @drift-labs/sdk,
// and friends depend on old @solana/web3.js/protobufjs/uuid/@grpc-js internally) or,
// for sharp, an inherited native-library CVE with no upstream fix published yet even
// on the latest sharp release. None of these have a fix that doesn't mean either
// and friends depend on old @solana/web3.js/protobufjs/uuid/@grpc-js internally).
// None of these have a fix that doesn't mean either
// downgrading a currently-working trading integration or forcing a major bump whose
// breaking changes haven't been vetted (e.g. @drift-labs/sdk's suggested fix requires
// Node 24, a separate decision from a routine audit pass).
@@ -38,10 +37,6 @@
"GHSA-wcpc-wj8m-hjx6",
"GHSA-f38q-mgvj-vph7",
// sharp — inherited libvips CVEs. Already on the latest sharp (0.35.4, bumped this
// same pass); no newer release exists yet that fixes the underlying libvips CVEs.
"GHSA-f88m-g3jw-g9cj",
// uuid — v3/v5/v6 buffer-bounds check (the v4 generator is unaffected). Verified
// node-cron's own source only calls uuid.v4() (scheduled-task.js, storage.js).
// The other path, @wormhole-foundation/sdk-solana's pinned rpc-websockets, has no
@@ -50,12 +45,10 @@
// a closer look, not as verified-safe the way node-cron's path is.
"GHSA-w5hq-g745-h8pq",
// extract-zip — symlink path-traversal, via puppeteer>@puppeteer/browsers. No
// patched version published yet. extract-zip is only used by @puppeteer/browsers'
// own setup step to unpack the pinned, official Chromium build it downloads from
// Google's CDN — CloddsBot never feeds it a user-controlled or otherwise untrusted
// zip (the actual PDF-export feature in src/extensions/open-prose only drives an
// already-launched browser; it doesn't touch this download/extract path).
"GHSA-jmr9-qjv8-65gv"
// stream-json — quadratic behavior is confined to the pick/ignore/filter/replace
// helpers. The only production consumer is jayson, which imports StreamValues and
// Verifier instead. jayson 4.3 pins stream-json 1.x and is incompatible with the
// patched 3.x module paths, so forcing the major would break Solana RPC parsing.
"GHSA-528h-pc64-c93x"
]
}
+297 -724
View File
File diff suppressed because it is too large Load Diff
+5 -3
View File
@@ -138,7 +138,7 @@
"json5": "^2.2.3",
"mammoth": "^1.11.0",
"node-cron": "^3.0.3",
"nodemailer": "^9.0.6",
"nodemailer": "^9.1.1",
"pg": "^8.17.2",
"pino": "^8.18.0",
"pino-pretty": "^10.3.1",
@@ -165,7 +165,9 @@
"@cosmjs/stargate": "^0.38.1",
"@cosmjs/tendermint-rpc": "^0.38.1",
"@cosmjs/cosmwasm-stargate": "^0.38.1",
"@solana/kit": "^5.0.0"
"@solana/kit": "^5.0.0",
"sharp": "$sharp",
"toml": "^4.2.0"
},
"devDependencies": {
"@types/express": "^4.17.21",
@@ -174,7 +176,7 @@
"@types/nodemailer": "^6.4.22",
"@types/sql.js": "^1.4.9",
"@types/ws": "^8.5.10",
"puppeteer": "^24.37.5",
"puppeteer": "^25.10.0",
"tsx": "^4.7.0",
"typescript": "^5.3.3"
}