chore: reduce and document dependency risk
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
# Dependency security audit
|
||||
|
||||
Audit date: 2026-07-29
|
||||
|
||||
## Outcome
|
||||
|
||||
- Runtime/production dependency audit: **0 vulnerabilities** (`npm audit --omit=dev`).
|
||||
- Full development toolchain: **19 high advisories**, reduced from 23.
|
||||
- Critical advisories: **0**.
|
||||
|
||||
Playwright was upgraded from 1.55.0 to 1.62.0, removing the browser-download
|
||||
certificate-verification advisory. `c8` was upgraded from 10.1.3 to 12.0.0,
|
||||
removing the vulnerable `test-exclude` chain. Compatible patched
|
||||
`brace-expansion` releases were installed where dependency ranges allowed it.
|
||||
|
||||
## Remaining development-only chain
|
||||
|
||||
All remaining records collapse to one advisory:
|
||||
`GHSA-mh99-v99m-4gvg`, an uncontrolled brace-expansion denial of service. npm
|
||||
reports it through nested `minimatch` versions in two independent toolchains:
|
||||
|
||||
- ESLint 10.8.0 (`@eslint/config-array`, `@eslint/eslintrc`);
|
||||
- electron-builder 26.15.3 (`@electron/asar`, `@electron/universal`, `glob`,
|
||||
`dir-compare`, `ejs`/`jake`, Windows packaging helpers).
|
||||
|
||||
These packages are never loaded by the packaged ForgeFlow runtime. They run in
|
||||
developer or CI processes against repository and build configuration owned by
|
||||
the operator. A malicious repository could still attempt resource exhaustion
|
||||
during linting or packaging, so the finding is not classified as harmless.
|
||||
CI jobs must retain memory/time limits and untrusted pull requests must not run
|
||||
release signing or publishing jobs.
|
||||
|
||||
## Decisions
|
||||
|
||||
- `npm audit fix --force` is prohibited. npm proposes ESLint 4.0.0 and an older
|
||||
electron-builder; both are breaking downgrades and the tested older builder
|
||||
dependency graph increased the result to 30 high and 1 critical advisory.
|
||||
- No global `minimatch` override is used. Several affected consumers declare
|
||||
older APIs, and forcing a new major could silently break packaging or lint
|
||||
file selection.
|
||||
- Latest stable ESLint and electron-builder versions are pinned exactly. The
|
||||
residual chain will be retested whenever either publishes a dependency fix.
|
||||
|
||||
The release gate treats `npm audit --omit=dev --audit-level=high` as blocking.
|
||||
The complete development audit remains documented and visible rather than
|
||||
being misrepresented as a production vulnerability count.
|
||||
Reference in New Issue
Block a user