# Dependency security audit Audit date: 2026-07-29 ## Outcome - Runtime/production dependency audit: **0 vulnerabilities** (`npm audit --omit=dev`). - Full development toolchain: **19 high advisories**, reduced from 23. - Critical advisories: **0**. Playwright was upgraded from 1.55.0 to 1.62.0, removing the browser-download certificate-verification advisory. `c8` was upgraded from 10.1.3 to 12.0.0, removing the vulnerable `test-exclude` chain. Compatible patched `brace-expansion` releases were installed where dependency ranges allowed it. ## Remaining development-only chain All remaining records collapse to one advisory: `GHSA-mh99-v99m-4gvg`, an uncontrolled brace-expansion denial of service. npm reports it through nested `minimatch` versions in two independent toolchains: - ESLint 10.8.0 (`@eslint/config-array`, `@eslint/eslintrc`); - electron-builder 26.15.3 (`@electron/asar`, `@electron/universal`, `glob`, `dir-compare`, `ejs`/`jake`, Windows packaging helpers). These packages are never loaded by the packaged ForgeFlow runtime. They run in developer or CI processes against repository and build configuration owned by the operator. A malicious repository could still attempt resource exhaustion during linting or packaging, so the finding is not classified as harmless. CI jobs must retain memory/time limits and untrusted pull requests must not run release signing or publishing jobs. ## Decisions - `npm audit fix --force` is prohibited. npm proposes ESLint 4.0.0 and an older electron-builder; both are breaking downgrades and the tested older builder dependency graph increased the result to 30 high and 1 critical advisory. - No global `minimatch` override is used. Several affected consumers declare older APIs, and forcing a new major could silently break packaging or lint file selection. - Latest stable ESLint and electron-builder versions are pinned exactly. The residual chain will be retested whenever either publishes a dependency fix. The release gate treats `npm audit --omit=dev --audit-level=high` as blocking. The complete development audit remains documented and visible rather than being misrepresented as a production vulnerability count.