chore(security): daily npm bundle 2026-08-26 — website lockfile - #8
Merged
Merged
Conversation
…-08-26) Resolves all 7 open audit findings (5 high, 2 moderate) in website/package-lock.json: Direct bumps (in-range): - next ^15.1.0 -> ^15.5.21 (locked 15.5.24): middleware/proxy bypass, cache poisoning, XSS, SSRF, DoS advisories incl. GHSA-26hh-7cqf-hhc6, GHSA-4633-3j49-mh5q, GHSA-955p-x3mx-jcvp and 19 others - mermaid ^11.14.0 -> ^11.16.1 (locked 11.17.2): CSS injection, prototype pollution, infinite-loop DoS (GHSA-c4c3-pg64-4m4v et al.) Transitive (in-range lockfile updates): - dompurify 3.4.2 -> 3.4.14, js-yaml 3.14.2 -> 3.15.1, nanoid 3.3.12 -> 3.3.18, sharp 0.34.5 -> 0.35.4 (GHSA-f88m-g3jw-g9cj; @img/* platform set churn expected) Override: - postcss ^8.5.26 via npm overrides: next pins postcss@8.4.31 exactly (GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849 et al.); the nested copy dedupes to a single patched 8.5.26. Lockfile regenerated scoped via npm install --package-lock-only. Verified locally: npm ci and npm run build (static export to out/) green. npm audit: 0 vulnerabilities. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HEc2tfuDB6bW3zEf26muST
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Daily security sweep bundle for the website lockfile (
website/package.json/website/package-lock.json).Vulnerabilities resolved (5 high, 2 moderate)
Direct bumps (in-range):
^15.1.0→^15.5.21^11.14.0→^11.16.1Transitive (in-range lockfile updates): dompurify 3.4.2 → 3.4.14 (10 sanitization-bypass advisories), js-yaml 3.14.2 → 3.15.1 (quadratic-CPU DoS), nanoid 3.3.12 → 3.3.18 (loop DoS), sharp 0.34.5 → 0.35.4 (GHSA-f88m-g3jw-g9cj, inherited libvips CVEs — the large
@img/*platform-package churn in the diff is the expected consequence).Override:
"overrides": { "postcss": "^8.5.26" }— next pinspostcss@8.4.31exactly, which sits in the vulnerable range of GHSA-fxqj-rqcc-2cmp / GHSA-r28c-9q8g-f849 (sourceMappingURL file read / path traversal) and can't be fixed in-range short of next@16 (semver-major). The global override is safe here (postcss is not a root direct dependency, so no EOVERRIDE) and dedupes the nested copy to a single patched 8.5.26.Dependabot alert numbers
403: GitHub access is not enabled for this session— the sweep ran in a remote Claude Code session without raw API access), so alert numbers (#NNN) could not be listed. Advisories are identified by GHSA ID above; the corresponding open alerts on this lockfile should auto-close on merge. A future run with API access can cross-reference by GHSA ID.Verification
npm audit(package-lock-only): 0 vulnerabilities (was 5 high / 2 moderate)npm ci✅ ·npm run build✅ (static export towebsite/outproduced — the checkpages.ymlruns)npm run lint(next lint): not a usable check either before or after this bump — the repo has no ESLint config, sonext lintdrops into interactive ESLint setup on the baseline too, and the subcommand is deprecated in 15.5 (prompts to migrate to the ESLint CLI). Website lint is not part of CI (pages.ymlruns install + build only). Worth setting up the ESLint CLI separately at some point.npm install --package-lock-only+npm audit fix --package-lock-only; no--force, no--legacy-peer-depsDo not merge automatically — maintainer's decision.
Generated by Claude Code