Repository navigation
fix(deps): resolve vitest/mocker path traversal and js-yaml DoS advisories - #20
Merged
Merged
Conversation
…ories Bumps vitest and @vitest/coverage-v8 to 4.1.11, the first version that patches GHSA-82fw-gwwq-j7x9 (Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock), same fix Dependabot PR #13 targets, but staying on the 4.x line instead of jumping to 5.0.0. vitest 5.0.0 requires Node >=22.12, which would break the node-20 leg of this repo's CI matrix and its own engines.node >=20; 4.1.11 has no such requirement and resolves both open vitest alerts (#21, #22) cleanly. Adds an npm override pinning js-yaml to ^4.3.2, patching GHSA-2883-xcg3-v3hh (#24, High). js-yaml is a transitive dev-only dependency via eslint -> @eslint/eslintrc, not reachable from any shipped code path, but it was failing the npm audit --audit-level=high CI gate. Verified locally end to end: lint, typecheck, coverage (24 tests), build, demo, and npm audit --audit-level=high all pass with 0 vulnerabilities reported. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vitestand@vitest/coverage-v8to4.1.11, the first patched version for GHSA-82fw-gwwq-j7x9 (fixes alerts ci: use npm ci over npm install, pin npm CLI, move audit earlier #21, fix(adapters)!: Anthropic and Bedrock input_tokens now inclusive of cache tokens #22). Dependabot's own PR build(deps): bump @vitest/mocker from 3.2.7 to 5.0.0 in the npm_and_yarn group across 0 directory #13 jumps to5.0.0, which requires Node >=22.12 and would break thenode-20leg of this repo's CI matrix plus its ownengines.node: >=20.4.1.11supports Node 20/22/24+ and has the same fix.overridesentry pinning the transitivejs-yaml(viaeslint -> @eslint/eslintrc) to^4.3.2, the patched version for GHSA-2883-xcg3-v3hh (fixes alert fix(cli): sanitize parse errors, validate flags, safe writes, no-network CI check #24). Dev-only, not reachable from shipped code, but it was failing thenpm audit --audit-level=highCI gate.Test plan
Ran the full CI pipeline locally end to end on the resolved dependency tree:
npm run lintnpm run typechecknpm run coverage(24 tests passing)npm run buildnpm run demonpm audit --audit-level=high-> 0 vulnerabilitiesSupersedes #13, which stays open with a comment explaining the narrower fix; safe to close once this merges.
🤖 Generated with Claude Code