Skip to content

fix(deps): patch js-yaml and svgo advisories blocking Security Scanning #2089

Description

@cristim

The frontend lockfile on main at eac9a62 contains js-yaml 3.15.1 and 4.3.1 plus svgo 4.0.2. Running npm audit --audit-level=high reports two high-severity vulnerable packages and exits 1, blocking Security Scanning and CI Success. PR2071 run34415153948 reproduces this with a lockfile identical to main.

Current advisories:

Update frontend/package-lock.json within the existing parent ranges, including SVGO's required selector dependencies. Preserve package.json and the full-tree audit gate. Verify audit red before and green after, production frontend build, and Jest.

Related LeanerCloud/cloud-commitments-platform#79 covers earlier fast-uri/SVGO advisories; LeanerCloud/cloud-commitments-platform#165 covers the broader gating policy. Neither tracks these current advisory versions. All affected entries are dev dependencies; this report establishes CI failure and vulnerable installed versions, not production exploitability.

Activity

  1. cristim commented on Sep 9, 2026

    @cristim
    MemberAuthor

    Prepared local commit 2751481 on fix/npm-yaml-svgo-advisories: only frontend/package-lock.json changes (32 additions, 19 deletions). Native macOS Node 26.8.1 verification passed: baseline audit reproduced two high-severity vulnerable packages; updated full audit reports zero vulnerabilities; npm ci --ignore-scripts, production build, typecheck, lint and all 90 Jest suites passed (2890 tests, one skipped). Build retains its entrypoint-size warning and lint reports 125 existing warnings. Normal git-secrets/Trivy commit hooks passed without bypasses. The clean commit is held locally, not pushed or merged. Node 24 CI, substantive CodeRabbit and the exact final-head Fable 5.1 review remain pending; Fable capacity is currently unavailable. This dependency fix must land before PR #2071 can rebase and repeat its final gates.

  2. cristim commented on Sep 11, 2026

    @cristim
    MemberAuthor

    Merged via PR #2090 as 5405fd1e90dffdb701a46d4b93868b947e1fbf05 on 2026-09-11 at 16:48:11 UTC.

    Verified: fetched origin/main and compared Git trees. The merge commit and reviewed PR head 3f74875049e191c7c27e829b50fc78c346807ba0 both have tree 8b9612dd17e56b9134f8bfc17c7c40b0141ed6cd. Thus the earlier native build/Jest consumer verification applies to identical files. A fresh native macOS Node 26.8.1 npm audit --audit-level=high returned found 0 vulnerabilities (exit 0), and the isolated worktree remains clean. No dependencies were reinstalled.

    Main-branch verification is still pending: individual background watchers cover all nine workflows at the exact merge SHA, including the automatically triggered deployment workflows. Prior PR CI success is not being treated as main CI success. No deployed-browser or live-cloud test has been performed, and this agent has not initiated a deployment.

    Follow-up: existing LeanerCloud/cloud-commitments-platform#74 now tracks the transient govulncheck network failures observed during PR verification. No duplicate issue was created. The issue's closed state came from the PR closing reference; this comment records the actual verification boundary. A terminal main-workflow result will follow.

  3. cristim commented on Sep 11, 2026

    @cristim
    MemberAuthor

    Post-merge verification complete for PR #2090, squash commit 5405fd1e90dffdb701a46d4b93868b947e1fbf05.

    All nine exact-merge-SHA workflows completed successfully:

    Workflow Run
    CI - Build & Test 34624083161
    frontend-build-sentinel 34624083174
    Frontend E2E 34624083239
    pre-commit 34624083179
    AWS Sanity (Read-only Dry Run) 34624083108
    Azure Sanity (Read-only Dry Run) 34624083181
    Deploy to AWS Lambda 34624083168
    Deploy to GCP Cloud Run 34624083164
    Deploy to Azure Container Apps 34624083243

    The merge tree equals the reviewed PR-head tree: 8b9612dd17e56b9134f8bfc17c7c40b0141ed6cd. Earlier native Node 26 build/Jest consumer evidence therefore applies to identical files. A fresh native macOS Node 26.8.1 npm audit --audit-level=high again returned found 0 vulnerabilities, exit 0. The isolated worktree remains preserved; no dependencies were reinstalled and no source changes were made during post-merge verification.

    The deployment results above are GitHub Actions conclusions only. No independent deployed-browser or live-cloud test was performed, and this agent did not initiate deployments or cloud mutations. This dependency/configuration issue can remain closed based on the verified audit fix, identical reviewed tree and successful main workflows.

    Follow-up issues filed: none. Existing LeanerCloud/cloud-commitments-platform#74 was updated by the parent with the earlier proxy download-failure evidence and retriaged; it tracks that separate network-resilience concern without a duplicate issue. All watcher logs remain preserved at /private/tmp/claude/cudly-2089-ci-<run-id>.log, together with the earlier attempt-specific failure logs.

  4. added a commit that references this issue on Sep 27, 2026
    ea7ec31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions