chore(plugins): refresh the locked transitive tree to clear npm audit - #16
Merged
Merged
Conversation
The security job has failed on `npm audit --audit-level=moderate` since the v0.7.0 publish. The finding is hono: the fix for CVE-2026-39408 was incomplete, so `toSSG()` can still write outside its target directory. hono arrives through @modelcontextprotocol/sdk, which memory-mcp depends on. Nothing here calls `toSSG()` -- it is Hono's static site generator -- so the advisory is not reachable from this code. The gate is set at moderate, though, and a red security job on every push is a gate nobody reads. Updating the SDK alone does not clear it: the lockfile pins the transitive tree separately, so the five packages carrying advisories have to be refreshed by name. Only the lockfile moves; no package.json range changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this fixes
The
securityjob has failed onnpm audit --audit-level=moderatesincethe v0.7.0 publish (run 34938439907, 2026-09-15), and on every push since,
including the v0.7.2 sync. This clears it.
The finding
honoarrives transitively:@everme/memory-mcp->@modelcontextprotocol/sdk->
hono/@hono/node-server.Not reachable from this code.
toSSG()is Hono's static site generator.memory-mcp serves MCP over its own transport and never calls it. This is
gate hygiene, not an exposed vulnerability -- but a job that is red on every
push is a job nobody reads, which is the actual risk.
Why the obvious fix does not work
npm audit fix --package-lock-onlyreports 0 changes, and bumping the SDKalone moves
@modelcontextprotocol/sdkto 1.30.0 while leavinghonoat4.12.31: the lockfile pins the transitive tree independently of its parent,
so the advisory-carrying packages have to be named. This refreshes the five
of them together, which is also what keeps the tree internally consistent.
hono@hono/node-serverfast-uriip-addressqsVerification
npm audit --audit-level=moderate: 0 vulnerabilities (was 1 moderate)npm ciclean, thennpm test --workspaces: all 10 workspaces pass, 0failures (360 tests)
plugins/package-lock.jsonand nothing else.No
package.jsonrange moves, so no published package changes itsdeclared dependencies.
Scope note
This is the mirror's own lockfile. The internal source repository carries a
separate lockfile with a different workspace set, and it is further behind:
5 advisories there, 2 of them high. That is fixed separately; it does not
block this.