Skip to content

chore(plugins): refresh the locked transitive tree to clear npm audit - #16

Merged
alwaysday1 merged 1 commit into
mainfrom
chore/refresh_plugins_lockfile_advisories
Sep 22, 2026
Merged

alwaysday1 merged 1 commit into
mainfrom
chore/refresh_plugins_lockfile_advisories

Conversation

@alwaysday1

Copy link
Copy Markdown
Collaborator

What this fixes

The security job has failed on npm audit --audit-level=moderate since
the v0.7.0 publish (run 34938439907, 2026-09-15), and on every push since,
including the v0.7.2 sync. This clears it.

The finding

moderate  hono  <=4.13.4  fixAvailable
          Hono: incomplete fix for CVE-2026-39408 -- toSSG() still
          writes files outside the target directory

hono arrives transitively: @everme/memory-mcp -> @modelcontextprotocol/sdk
-> hono / @hono/node-server.

Not reachable from this code. toSSG() is Hono's static site generator.
memory-mcp serves MCP over its own transport and never calls it. This is
gate hygiene, not an exposed vulnerability -- but a job that is red on every
push is a job nobody reads, which is the actual risk.

Why the obvious fix does not work

npm audit fix --package-lock-only reports 0 changes, and bumping the SDK
alone moves @modelcontextprotocol/sdk to 1.30.0 while leaving hono at
4.12.31: the lockfile pins the transitive tree independently of its parent,
so the advisory-carrying packages have to be named. This refreshes the five
of them together, which is also what keeps the tree internally consistent.

package before after
hono 4.13.3 4.13.8
@hono/node-server 2.1.1 2.1.1
fast-uri 3.1.7 3.1.8
ip-address 10.5.0 10.7.2
qs 6.16.0 6.16.0

Verification

  • npm audit --audit-level=moderate: 0 vulnerabilities (was 1 moderate)
  • npm ci clean, then npm test --workspaces: all 10 workspaces pass, 0
    failures (360 tests)
  • Diff is 9 lines changed in plugins/package-lock.json and nothing else.
    No package.json range moves, so no published package changes its
    declared dependencies.

Scope note

This is the mirror's own lockfile. The internal source repository carries a
separate lockfile with a different workspace set, and it is further behind:
5 advisories there, 2 of them high. That is fixed separately; it does not
block this.

The security job has failed on `npm audit --audit-level=moderate` since the
v0.7.0 publish. The finding is hono: the fix for CVE-2026-39408 was
incomplete, so `toSSG()` can still write outside its target directory.

hono arrives through @modelcontextprotocol/sdk, which memory-mcp depends on.
Nothing here calls `toSSG()` -- it is Hono's static site generator -- so the
advisory is not reachable from this code. The gate is set at moderate,
though, and a red security job on every push is a gate nobody reads.

Updating the SDK alone does not clear it: the lockfile pins the transitive
tree separately, so the five packages carrying advisories have to be
refreshed by name. Only the lockfile moves; no package.json range changes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@alwaysday1
alwaysday1 merged commit 5e2f7db into main Sep 22, 2026
7 checks passed
@alwaysday1
alwaysday1 deleted the chore/refresh_plugins_lockfile_advisories branch September 22, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants