Skip to content

chore(site): take in-range security updates in the lockfile - #171

Merged
Seungpyo1007 merged 1 commit into
developfrom
chore/site-deps-in-range
Sep 11, 2026
Merged

Seungpyo1007 merged 1 commit into
developfrom
chore/site-deps-in-range

Conversation

@Seungpyo1007

@Seungpyo1007 Seungpyo1007 commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Lockfile-only security update for the site. package.json is unchanged — every bump stays inside the ranges already declared.

js-yaml     4.1.1  -> 4.3.2      smol-toml  1.6.1  -> 1.8.0
nanoid      3.3.12 -> 3.3.19     svgo       4.0.1  -> 4.1.0
postcss     8.5.15 -> 8.5.28     vite       6.4.2  -> 6.4.3
css-select  5.2.2  -> 6.0.0      css-what   6.2.2  -> 7.0.0
sax         1.6.0  -> 1.6.1

npm audit goes from 9 vulnerabilities (1 critical, 7 high, 1 low) to 3.

Verified by building — CI does not

TechAPI's PR checks validate data but never build the site; the build only runs on deploy from main. So the site was built locally both ways, from a checkout without the million-file dump (astro build, skipping prebuild, which needs index.json's git history):

lockfile npm ci astro build pages dist files warnings / errors
current ok ok 2 7 0
this PR ok ok 2 7 0

What is left, and why it is not in this PR

The remaining three — astro (critical), sharp (high), esbuild (low) — only clear with astro 5 → 7, a semver-major upgrade that needs its own migration and review.

Actual exposure is low in the meantime:

  • The critical astro advisories are XSS through define:vars and replay of server-island parameters. The site uses neither — no define:vars anywhere in site/src, and it is a static build (no output: server, no adapter).
  • sharp, esbuild, and most of what this PR fixes (vite / esbuild dev servers, launch-editor, postcss source maps) run on the build machine, not in what visitors download.

Refs #1

Closes #19

npm audit fix --package-lock-only; package.json is unchanged, so every
bump stays inside the declared ranges. 9 advisories drop to 3. The site
builds identically before and after (2 pages, 7 files, no warnings).

The remaining three (astro, sharp, esbuild) need astro 5 -> 7, a major
upgrade left for its own change. The critical astro advisories need
define:vars or server islands, and this static site uses neither.

Refs #1
@Seungpyo1007 Seungpyo1007 self-assigned this Sep 11, 2026
@github-actions github-actions Bot added enhancement New feature or request site Homepage and public site changes labels Sep 11, 2026
@Seungpyo1007 Seungpyo1007 moved this from Todo to In Progress in TechAPI-Project Sep 11, 2026
@Seungpyo1007

Copy link
Copy Markdown
Member Author

Output check: the two builds (current lockfile vs this PR) were compared file by file. All 7 files in dist/ — including the content-hashed _astro/*.js and *.css bundles — are byte-identical. The update changes nothing a visitor downloads; it only changes what runs on the build machine.

@Seungpyo1007
Seungpyo1007 merged commit cd53784 into develop Sep 11, 2026
2 checks passed
@Seungpyo1007
Seungpyo1007 deleted the chore/site-deps-in-range branch September 11, 2026 03:03
@github-project-automation github-project-automation Bot moved this from In Progress to Done in TechAPI-Project Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request site Homepage and public site changes

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Track homepage and site improvements

1 participant