Skip to content

fix(deps): clear the high-severity npm audit findings - #43

Merged
KazKozDev merged 1 commit into
mainfrom
fix/npm-audit-high
Oct 8, 2026
Merged

KazKozDev merged 1 commit into
mainfrom
fix/npm-audit-high

Conversation

@KazKozDev

Copy link
Copy Markdown
Owner

What this changes

Updates core/package-lock.json so npm audit --audit-level=high passes again. No source file and no version range in package.json changes.

Why

The nightly audit workflow has failed every night since late September. It reported 10 advisories, 5 of them high, all in transitive dependencies: adm-zip, brace-expansion, sharp and source-map-js (high), plus smol-toml, sprintf-js and what depends on it (moderate). Every one had a fix inside the ranges already allowed, so npm audit fix clears all ten.

How it was verified

  • npm audit --audit-level=high — "found 0 vulnerabilities", exit 0 (was exit 1)
  • npm ci, then typecheck, lint, test (45 files, 318 tests) and build pass locally
  • ./scripts/check.sh as a whole was not run: deadcode and shellcheck were skipped
  • Not loaded in Chrome and no browser eval run. sharp and @huggingface/transformers are among the updated packages, so the local-embedding path is the one worth a manual look.

Notes

🤖 Generated with Claude Code

The nightly audit has failed since late September on five high advisories
in transitive dependencies: adm-zip, brace-expansion, sharp and
source-map-js. `npm audit fix` resolves all ten findings, moderate ones
included, within the ranges package.json already allows; only the lockfile
changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T15:34:36.448641Z b77ce54 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@KazKozDev
KazKozDev merged commit e094867 into main Oct 8, 2026
5 checks passed
@KazKozDev
KazKozDev deleted the fix/npm-audit-high branch October 8, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant