2.2 KiB
Dependency security audit
Audit date: 2026-07-29
Outcome
- Runtime/production dependency audit: 0 vulnerabilities (
npm audit --omit=dev). - Full development toolchain: 19 high advisories, reduced from 23.
- Critical advisories: 0.
Playwright was upgraded from 1.55.0 to 1.62.0, removing the browser-download
certificate-verification advisory. c8 was upgraded from 10.1.3 to 12.0.0,
removing the vulnerable test-exclude chain. Compatible patched
brace-expansion releases were installed where dependency ranges allowed it.
Remaining development-only chain
All remaining records collapse to one advisory:
GHSA-mh99-v99m-4gvg, an uncontrolled brace-expansion denial of service. npm
reports it through nested minimatch versions in two independent toolchains:
- ESLint 10.8.0 (
@eslint/config-array,@eslint/eslintrc); - electron-builder 26.15.3 (
@electron/asar,@electron/universal,glob,dir-compare,ejs/jake, Windows packaging helpers).
These packages are never loaded by the packaged ForgeFlow runtime. They run in developer or CI processes against repository and build configuration owned by the operator. A malicious repository could still attempt resource exhaustion during linting or packaging, so the finding is not classified as harmless. CI jobs must retain memory/time limits and untrusted pull requests must not run release signing or publishing jobs.
Decisions
npm audit fix --forceis prohibited. npm proposes ESLint 4.0.0 and an older electron-builder; both are breaking downgrades and the tested older builder dependency graph increased the result to 30 high and 1 critical advisory.- No global
minimatchoverride is used. Several affected consumers declare older APIs, and forcing a new major could silently break packaging or lint file selection. - Latest stable ESLint and electron-builder versions are pinned exactly. The residual chain will be retested whenever either publishes a dependency fix.
The release gate treats npm audit --omit=dev --audit-level=high as blocking.
The complete development audit remains documented and visible rather than
being misrepresented as a production vulnerability count.