47 lines
2.2 KiB
Markdown
47 lines
2.2 KiB
Markdown
# Dependency security audit
|
|
|
|
Audit date: 2026-07-29
|
|
|
|
## Outcome
|
|
|
|
- Runtime/production dependency audit: **0 vulnerabilities** (`npm audit --omit=dev`).
|
|
- Full development toolchain: **19 high advisories**, reduced from 23.
|
|
- Critical advisories: **0**.
|
|
|
|
Playwright was upgraded from 1.55.0 to 1.62.0, removing the browser-download
|
|
certificate-verification advisory. `c8` was upgraded from 10.1.3 to 12.0.0,
|
|
removing the vulnerable `test-exclude` chain. Compatible patched
|
|
`brace-expansion` releases were installed where dependency ranges allowed it.
|
|
|
|
## Remaining development-only chain
|
|
|
|
All remaining records collapse to one advisory:
|
|
`GHSA-mh99-v99m-4gvg`, an uncontrolled brace-expansion denial of service. npm
|
|
reports it through nested `minimatch` versions in two independent toolchains:
|
|
|
|
- ESLint 10.8.0 (`@eslint/config-array`, `@eslint/eslintrc`);
|
|
- electron-builder 26.15.3 (`@electron/asar`, `@electron/universal`, `glob`,
|
|
`dir-compare`, `ejs`/`jake`, Windows packaging helpers).
|
|
|
|
These packages are never loaded by the packaged ForgeFlow runtime. They run in
|
|
developer or CI processes against repository and build configuration owned by
|
|
the operator. A malicious repository could still attempt resource exhaustion
|
|
during linting or packaging, so the finding is not classified as harmless.
|
|
CI jobs must retain memory/time limits and untrusted pull requests must not run
|
|
release signing or publishing jobs.
|
|
|
|
## Decisions
|
|
|
|
- `npm audit fix --force` is prohibited. npm proposes ESLint 4.0.0 and an older
|
|
electron-builder; both are breaking downgrades and the tested older builder
|
|
dependency graph increased the result to 30 high and 1 critical advisory.
|
|
- No global `minimatch` override is used. Several affected consumers declare
|
|
older APIs, and forcing a new major could silently break packaging or lint
|
|
file selection.
|
|
- Latest stable ESLint and electron-builder versions are pinned exactly. The
|
|
residual chain will be retested whenever either publishes a dependency fix.
|
|
|
|
The release gate treats `npm audit --omit=dev --audit-level=high` as blocking.
|
|
The complete development audit remains documented and visible rather than
|
|
being misrepresented as a production vulnerability count.
|