mirror of
https://github.com/alsk1992/CloddsBot.git
synced 2026-10-02 02:54:40 +08:00
fix: remediate npm audit findings, replace plain npm audit with audit-ci
85 -> 62 production vulnerabilities (52 moderate, 9 high, 1 critical remain,
all allowlisted below) via two npm audit fix passes plus manual major-version
bumps for nodemailer (7 -> 9) and sharp (0.34 -> 0.35), chosen because both
have narrow, stable-surface usage in this codebase (createTransport/sendMail;
a basic resize/metadata chain) verified before bumping.
The sharp bump broke its own TS types in two places, both fixed:
- src/media/index.ts: sharp's ESM types now separately export a named
SharpConstructor and a default rather than making the module namespace
itself callable, breaking `typeof import('sharp')` as a cast target.
Replaced with a small local SharpFactory type describing only what this
file actually calls (resize/toFormat/toBuffer/metadata) — sharp has now
changed its export shape at least once, so pinning to its exact type
surface here was already fragile.
- src/extensions/open-prose/index.ts: an unrelated puppeteer version shift
(pulled in transitively during the audit-fix passes) dropped 'networkidle0'
as a valid page.setContent() waitUntil value (still valid for page.goto(),
just not setContent()) — switched to 'load', the correct equivalent for
rendering already-inlined HTML.
New audit-ci.jsonc allowlists the remaining findings with per-advisory
justification: almost all are protobufjs/@grpc-js/uuid pulled in transitively
by the Solana SDK ecosystem's own pinned old @solana/web3.js/@coral-xyz/anchor
versions (Drift, Orca, Kamino, Raydium, etc.) — none fixable without either
downgrading a trading integration this session verified working, or forcing
a major bump whose breaking changes (e.g. @drift-labs/sdk needing Node 24)
haven't been vetted. sharp's one remaining finding is an inherited libvips
CVE with no fix published yet even on the latest release just installed here.
ci.yml and security.yml now run `audit-ci --config audit-ci.jsonc` instead of
plain `npm audit`, since plain npm audit has no allowlist mechanism at all —
without this, the allowlist above would have no effect on actual CI results.
This commit is contained in:
+2
-2
@@ -134,11 +134,11 @@
|
||||
"json5": "^2.2.3",
|
||||
"mammoth": "^1.11.0",
|
||||
"node-cron": "^3.0.3",
|
||||
"nodemailer": "^7.0.13",
|
||||
"nodemailer": "^9.0.6",
|
||||
"pg": "^8.17.2",
|
||||
"pino": "^8.18.0",
|
||||
"pino-pretty": "^10.3.1",
|
||||
"sharp": "^0.34.5",
|
||||
"sharp": "^0.35.4",
|
||||
"sql.js": "^1.14.0",
|
||||
"tiktoken": "^1.0.22",
|
||||
"tmi.js": "^1.8.5",
|
||||
|
||||
Reference in New Issue
Block a user