Files
ForgeFlow/docs/DEPENDENCY_AUDIT.md

2.2 KiB

Dependency security audit

Audit date: 2026-07-29

Outcome

  • Runtime/production dependency audit: 0 vulnerabilities (npm audit --omit=dev).
  • Full development toolchain: 19 high advisories, reduced from 23.
  • Critical advisories: 0.

Playwright was upgraded from 1.55.0 to 1.62.0, removing the browser-download certificate-verification advisory. c8 was upgraded from 10.1.3 to 12.0.0, removing the vulnerable test-exclude chain. Compatible patched brace-expansion releases were installed where dependency ranges allowed it.

Remaining development-only chain

All remaining records collapse to one advisory: GHSA-mh99-v99m-4gvg, an uncontrolled brace-expansion denial of service. npm reports it through nested minimatch versions in two independent toolchains:

  • ESLint 10.8.0 (@eslint/config-array, @eslint/eslintrc);
  • electron-builder 26.15.3 (@electron/asar, @electron/universal, glob, dir-compare, ejs/jake, Windows packaging helpers).

These packages are never loaded by the packaged ForgeFlow runtime. They run in developer or CI processes against repository and build configuration owned by the operator. A malicious repository could still attempt resource exhaustion during linting or packaging, so the finding is not classified as harmless. CI jobs must retain memory/time limits and untrusted pull requests must not run release signing or publishing jobs.

Decisions

  • npm audit fix --force is prohibited. npm proposes ESLint 4.0.0 and an older electron-builder; both are breaking downgrades and the tested older builder dependency graph increased the result to 30 high and 1 critical advisory.
  • No global minimatch override is used. Several affected consumers declare older APIs, and forcing a new major could silently break packaging or lint file selection.
  • Latest stable ESLint and electron-builder versions are pinned exactly. The residual chain will be retested whenever either publishes a dependency fix.

The release gate treats npm audit --omit=dev --audit-level=high as blocking. The complete development audit remains documented and visible rather than being misrepresented as a production vulnerability count.