Skip to content

fix(deps): resolve known security vulnerabilities#237

Merged
stevenfackley merged 5 commits into
mainfrom
claude/security-fixes
Jul 23, 2026
Merged

fix(deps): resolve known security vulnerabilities#237
stevenfackley merged 5 commits into
mainfrom
claude/security-fixes

Conversation

@stevenfackley

Copy link
Copy Markdown
Owner

Security sweep per GitHub/OSV advisories: brace-expansion override + npm audit fixes in src/StackAlchemist.Web. Lockfile-only; no downgrades.

🤖 Generated with Claude Code

https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1


Generated by Claude Code

claude and others added 5 commits July 20, 2026 21:21
Bump vulnerable dependencies flagged by the GitHub/OSV advisory database:
npm audit fixes, upward-only direct bumps, and scoped overrides for
transitive packages (brace-expansion, shell-quote, postcss, esbuild, ws,
undici, minimatch, glob, cookie); pnpm overrides; lockfile re-resolution.
No dependency was downgraded (verified against HEAD).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1
- Regenerate complete lockfiles with full npm install (npm ci was failing
  on missing entries from --package-lock-only updates)
- Constrain brace-expansion overrides per-major (1.1.16 / 2.1.2 / 5.0.7);
  the audit-fix '>=1.1.16' override was jumping minimatch's dependency
  across majors and breaking ESLint at runtime
- Cap vitest override at ~3.2.6 where vite 5 is in use (vitest 4 needs vite 6)
- ai-fit: add required TextArea props surfaced by react-native type bump

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1
* fix(deps): bump brace-expansion 5.0.6 -> 5.0.7

Clears Dependabot alert #48 (high, vulnerable range >=3.0.0 <5.0.7).
Root instance satisfies minimatch ^5.0.5; nested 1.1.x eslint-chain
copies are outside the vulnerable range (refreshed to 1.1.16 by the
same npm update).

* fix(deps): floor sharp at 0.35.0+ via override — clears npm audit gate

The CI Audit Dependencies step failed on sharp <0.35.0 (libvips CVEs,
GHSA-f88m-g3jw-g9cj). npm audit displayed this as a wall of next
advisories, but that was the metavulnerability rollup: next was flagged
only for depending on vulnerable sharp. Flooring sharp (0.34.5 ->
0.35.3) takes npm audit to 0 vulnerabilities; no gate change needed.

Same sharp@0 override pattern as haulcall and trailtold.
…est main)

Rebuilt from today's main and today's advisory set: npm audit fixes,
upward-only direct bumps, per-major overrides for transitive packages,
pnpm override sanitation, uv.lock/cargo/requirements updates.
Verified: no dependency downgraded; lockfiles npm-ci-consistent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1
…latest main)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1
@stevenfackley
stevenfackley merged commit 2e7a649 into main Jul 23, 2026
16 checks passed
@stevenfackley
stevenfackley deleted the claude/security-fixes branch July 23, 2026 07:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants