Skip to content

chore(security): daily npm bundle 2026-08-26 — website lockfile - #8

Merged
benfrank241 merged 1 commit into
mainfrom
chore/security-daily-20260826-npm-website
Aug 26, 2026
Merged

benfrank241 merged 1 commit into
mainfrom
chore/security-daily-20260826-npm-website

Conversation

@benfrank241

Copy link
Copy Markdown
Member

Daily security sweep bundle for the website lockfile (website/package.json / website/package-lock.json).

Vulnerabilities resolved (5 high, 2 moderate)

Direct bumps (in-range):

Package Declared Locked Advisories
next ^15.1.0 → ^15.5.21 15.5.15 → 15.5.24 22 advisories: middleware/proxy bypass (GHSA-26hh-7cqf-hhc6, GHSA-267c-6grr-h53f, GHSA-36qx-fr4f-26g5), cache poisoning/confusion (GHSA-3g8h-86w9-wvmq, GHSA-68g3-v927-f742, GHSA-4633-3j49-mh5q), XSS (GHSA-ffhc-5mcf-pf4q, GHSA-gx5p-jg67-6x7h), SSRF (GHSA-c4j6-fc7j-m34r, GHSA-89xv-2m56-2m9x, GHSA-p9j2-gv94-2wf4), DoS, server-function disclosure (GHSA-955p-x3mx-jcvp)
mermaid ^11.14.0 → ^11.16.1 11.14.0 → 11.17.2 CSS injection (GHSA-ghcm-xqfw-q4vr, GHSA-6x64-9x62-f2gx), prototype pollution (GHSA-c4c3-pg64-4m4v, GHSA-3rrr-jr9j-h3q3), infinite-loop DoS (GHSA-6m6c-36f7-fhxh, GHSA-2v8p-3f2j-5mp7, GHSA-rhh3-jpg6-66xh)

Transitive (in-range lockfile updates): dompurify 3.4.2 → 3.4.14 (10 sanitization-bypass advisories), js-yaml 3.14.2 → 3.15.1 (quadratic-CPU DoS), nanoid 3.3.12 → 3.3.18 (loop DoS), sharp 0.34.5 → 0.35.4 (GHSA-f88m-g3jw-g9cj, inherited libvips CVEs — the large @img/* platform-package churn in the diff is the expected consequence).

Override: "overrides": { "postcss": "^8.5.26" } — next pins postcss@8.4.31 exactly, which sits in the vulnerable range of GHSA-fxqj-rqcc-2cmp / GHSA-r28c-9q8g-f849 (sourceMappingURL file read / path traversal) and can't be fixed in-range short of next@16 (semver-major). The global override is safe here (postcss is not a root direct dependency, so no EOVERRIDE) and dedupes the nested copy to a single patched 8.5.26.

Dependabot alert numbers

⚠️ This run could not reach the Dependabot alerts API (403: GitHub access is not enabled for this session — the sweep ran in a remote Claude Code session without raw API access), so alert numbers (#NNN) could not be listed. Advisories are identified by GHSA ID above; the corresponding open alerts on this lockfile should auto-close on merge. A future run with API access can cross-reference by GHSA ID.

Verification

  • npm audit (package-lock-only): 0 vulnerabilities (was 5 high / 2 moderate)
  • npm ci ✅ · npm run build ✅ (static export to website/out produced — the check pages.yml runs)
  • npm run lint (next lint): not a usable check either before or after this bump — the repo has no ESLint config, so next lint drops into interactive ESLint setup on the baseline too, and the subcommand is deprecated in 15.5 (prompts to migrate to the ESLint CLI). Website lint is not part of CI (pages.yml runs install + build only). Worth setting up the ESLint CLI separately at some point.
  • Lockfile regenerated scoped via npm install --package-lock-only + npm audit fix --package-lock-only; no --force, no --legacy-peer-deps

Do not merge automatically — maintainer's decision.


Generated by Claude Code

…-08-26)

Resolves all 7 open audit findings (5 high, 2 moderate) in
website/package-lock.json:

Direct bumps (in-range):
- next ^15.1.0 -> ^15.5.21 (locked 15.5.24): middleware/proxy bypass,
  cache poisoning, XSS, SSRF, DoS advisories incl. GHSA-26hh-7cqf-hhc6,
  GHSA-4633-3j49-mh5q, GHSA-955p-x3mx-jcvp and 19 others
- mermaid ^11.14.0 -> ^11.16.1 (locked 11.17.2): CSS injection,
  prototype pollution, infinite-loop DoS (GHSA-c4c3-pg64-4m4v et al.)

Transitive (in-range lockfile updates):
- dompurify 3.4.2 -> 3.4.14, js-yaml 3.14.2 -> 3.15.1,
  nanoid 3.3.12 -> 3.3.18, sharp 0.34.5 -> 0.35.4 (GHSA-f88m-g3jw-g9cj;
  @img/* platform set churn expected)

Override:
- postcss ^8.5.26 via npm overrides: next pins postcss@8.4.31 exactly
  (GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849 et al.); the nested copy
  dedupes to a single patched 8.5.26.

Lockfile regenerated scoped via npm install --package-lock-only.
Verified locally: npm ci and npm run build (static export to out/)
green. npm audit: 0 vulnerabilities.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HEc2tfuDB6bW3zEf26muST
@benfrank241 benfrank241 added the security label Aug 26, 2026 — with Claude
@benfrank241
benfrank241 merged commit 9687e58 into main Aug 26, 2026
1 check passed
@benfrank241
benfrank241 deleted the chore/security-daily-20260826-npm-website branch August 26, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants