* fix(3588)(security): clear production npm-audit advisories Before: 6 production advisories (1 high, 5 moderate) reported by `npm audit --omit=dev` — fast-uri (high), @anthropic-ai/sdk, express-rate-limit, hono, ip-address (moderate), all pulled in through @anthropic-ai/claude-agent-sdk and @modelcontextprotocol/sdk. After: `npm audit fix` bumped the lockfile-pinned transitive versions to patched releases. No package.json edits — only package-lock.json and sdk/package-lock.json. Production audit is clean on both: `npm audit --omit=dev` → 0 vulnerabilities. Regression test `tests/bug-3588-npm-audit-clean.test.cjs` runs `npm audit --omit=dev --json` against root and sdk/ and asserts the metadata vulnerability counts are zero across info/low/moderate/high/ critical. RED on origin/main (1 high + 5 moderate at root), GREEN after the lockfile bumps. Skips gracefully when node_modules/ is absent so fresh checkouts mid-`npm install` don't false-fail. Fixes #3588 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(3588): npm audit harness throws on unexpected JSON shape CodeRabbit caught that auditProductionVulns returned null both for "node_modules missing → skip" AND for "unexpected JSON shape" — and callers interpret null uniformly as skip, so a real audit harness failure (npm changed output format, audit aborted before metadata section, etc.) would silently no-op instead of failing the test. null is now reserved for the skip signal only. Any other unexpected shape throws with the cwd in the message so the test fails loudly. Local: docker gsd-test-summary 11204/0 on plex2. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
427 B
427 B
type, pr
| type | pr |
|---|---|
| Security | 3588 |
npm audit --omit=dev is clean — bumped lockfile-pinned transitive versions of fast-uri, @anthropic-ai/sdk, hono, ip-address, and express-rate-limit (pulled in through @anthropic-ai/claude-agent-sdk and @modelcontextprotocol/sdk) to patched releases. Same pass applied to sdk/package-lock.json (was clean for production already; the test now locks it in). Resolves #3588.