chore(site): take in-range security updates in the lockfile - #171
Merged
Merged
Conversation
npm audit fix --package-lock-only; package.json is unchanged, so every bump stays inside the declared ranges. 9 advisories drop to 3. The site builds identically before and after (2 pages, 7 files, no warnings). The remaining three (astro, sharp, esbuild) need astro 5 -> 7, a major upgrade left for its own change. The critical astro advisories need define:vars or server islands, and this static site uses neither. Refs #1
Member
Author
|
Output check: the two builds (current lockfile vs this PR) were compared file by file. All 7 files in |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lockfile-only security update for the site.
package.jsonis unchanged — every bump stays inside the ranges already declared.npm auditgoes from 9 vulnerabilities (1 critical, 7 high, 1 low) to 3.Verified by building — CI does not
TechAPI's PR checks validate data but never build the site; the build only runs on deploy from
main. So the site was built locally both ways, from a checkout without the million-file dump (astro build, skippingprebuild, which needsindex.json's git history):npm ciastro buildWhat is left, and why it is not in this PR
The remaining three —
astro(critical),sharp(high),esbuild(low) — only clear with astro 5 → 7, a semver-major upgrade that needs its own migration and review.Actual exposure is low in the meantime:
astroadvisories are XSS throughdefine:varsand replay of server-island parameters. The site uses neither — nodefine:varsanywhere insite/src, and it is a static build (nooutput: server, no adapter).sharp,esbuild, and most of what this PR fixes (vite / esbuild dev servers, launch-editor, postcss source maps) run on the build machine, not in what visitors download.Refs #1
Closes #19