fix: remediate npm audit findings, replace plain npm audit with audit-ci

85 -> 62 production vulnerabilities (52 moderate, 9 high, 1 critical remain,
all allowlisted below) via two npm audit fix passes plus manual major-version
bumps for nodemailer (7 -> 9) and sharp (0.34 -> 0.35), chosen because both
have narrow, stable-surface usage in this codebase (createTransport/sendMail;
a basic resize/metadata chain) verified before bumping.

The sharp bump broke its own TS types in two places, both fixed:
- src/media/index.ts: sharp's ESM types now separately export a named
  SharpConstructor and a default rather than making the module namespace
  itself callable, breaking `typeof import('sharp')` as a cast target.
  Replaced with a small local SharpFactory type describing only what this
  file actually calls (resize/toFormat/toBuffer/metadata) — sharp has now
  changed its export shape at least once, so pinning to its exact type
  surface here was already fragile.
- src/extensions/open-prose/index.ts: an unrelated puppeteer version shift
  (pulled in transitively during the audit-fix passes) dropped 'networkidle0'
  as a valid page.setContent() waitUntil value (still valid for page.goto(),
  just not setContent()) — switched to 'load', the correct equivalent for
  rendering already-inlined HTML.

New audit-ci.jsonc allowlists the remaining findings with per-advisory
justification: almost all are protobufjs/@grpc-js/uuid pulled in transitively
by the Solana SDK ecosystem's own pinned old @solana/web3.js/@coral-xyz/anchor
versions (Drift, Orca, Kamino, Raydium, etc.) — none fixable without either
downgrading a trading integration this session verified working, or forcing
a major bump whose breaking changes (e.g. @drift-labs/sdk needing Node 24)
haven't been vetted. sharp's one remaining finding is an inherited libvips
CVE with no fix published yet even on the latest release just installed here.

ci.yml and security.yml now run `audit-ci --config audit-ci.jsonc` instead of
plain `npm audit`, since plain npm audit has no allowlist mechanism at all —
without this, the allowlist above would have no effect on actual CI results.
This commit is contained in:
alsk1992
2026-08-30 23:17:46 +01:00
parent ee7df0c10b
commit c4e65fa1af
7 changed files with 1270 additions and 931 deletions
+2 -2
View File
@@ -134,11 +134,11 @@
"json5": "^2.2.3",
"mammoth": "^1.11.0",
"node-cron": "^3.0.3",
"nodemailer": "^7.0.13",
"nodemailer": "^9.0.6",
"pg": "^8.17.2",
"pino": "^8.18.0",
"pino-pretty": "^10.3.1",
"sharp": "^0.34.5",
"sharp": "^0.35.4",
"sql.js": "^1.14.0",
"tiktoken": "^1.0.22",
"tmi.js": "^1.8.5",