diff --git a/plan.md b/plan.md index 960f8553..0982bd81 100644 --- a/plan.md +++ b/plan.md @@ -111,7 +111,7 @@ Use Node 24 because the current locked dependencies already install, lint, type- Baseline capture date: 2026-07-27. -The integration branch `agent/maintenance-security-and-hygiene` is represented by commit `500526abbb0d429787402ae6611058f31a9cc7f6` and draft pull request [#199](https://github.com/WordPress/try-wordpress/pull/199), which is open against `trunk`. Documentation-only execution-baseline child pull request [#200](https://github.com/WordPress/try-wordpress/pull/200) targets the integration branch. +The pre-child-019 integration branch anchor is commit `6189aabbaeef452d4f84b9eabe879b984ba6b480`, represented by `agent/maintenance-security-and-hygiene` and draft pull request [#199](https://github.com/WordPress/try-wordpress/pull/199), which remains open and unmerged against `trunk`. Documentation-only execution-baseline child pull request [#200](https://github.com/WordPress/try-wordpress/pull/200) was merged into the integration branch at merge commit `577ef6b1dbb6fce80f691a26767321fa7609b565`. ### Baseline Dependabot Summary @@ -150,19 +150,19 @@ Rows are ordered by remediation priority: severity first, runtime before develop | Alert | GHSA | Severity | Ecosystem | Affected package | Relationship / scope | Locked vulnerable version(s) | First patched | Causal family set | Representative locked path | Child PR | Status | | ---: | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| 44 | GHSA-95m3-7q98-8xr5 | critical | npm | `sha.js` | transitive / runtime | `2.4.11` | `2.4.12` | PGL | `sha.js@2.4.11 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | +| 44 | GHSA-95m3-7q98-8xr5 | critical | npm | `sha.js` | transitive / runtime | `2.4.11` | `2.4.12` | PGL | `sha.js@2.4.11 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | | 42 | GHSA-fjxv-7rqg-78g4 | critical | npm | `form-data` | transitive / development | `4.0.0` | `4.0.4` | WPS | `form-data@4.0.0 ← @wordpress/e2e-test-utils-playwright@1.7.0 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | | 77 | GHSA-5rq4-664w-9x2c | critical | npm | `basic-ftp` | transitive / development | `5.0.5` | `5.2.0` | WPS | `basic-ftp@5.0.5 ← get-uri@6.0.3 ← pac-proxy-agent@7.0.2 ← proxy-agent@6.4.0 ← @puppeteer/browsers@2.4.0 ← puppeteer-core@23.3.0 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | | 146 | GHSA-w7jw-789q-3m8p | critical | npm | `shell-quote` | transitive / development | `1.7.3, 1.8.1` | `1.8.4` | CONCURRENTLY + WEBEXT + WPS | `shell-quote@1.8.1 ← concurrently@9.1.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PR #202 removed the WPS and CONCURRENTLY paths; web-ext `10.4.0` replaces the last affected `1.7.3` path with patched `1.8.4`; vulnerable version absent globally in the integration branch | | 164 | GHSA-xv26-6w52-cph6 | critical | npm | `websocket-driver` | transitive / development | `0.7.4` | `0.7.5` | WPS | `websocket-driver@0.7.4 ← sockjs@0.3.24 ← webpack-dev-server@4.15.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | -| 3 | GHSA-pwfr-8pq7-x9qv | high | npm | `octokit` | transitive / runtime | `3.1.1` | `3.1.2` | PGL | `octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | -| 11 | GHSA-9wv6-86v2-598j | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.10` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 13 | GHSA-qwcr-r2fm-qrc7 | high | npm | `body-parser` | transitive / runtime | `1.20.2` | `1.20.3` | PGL + WEBEXT + WPS | `body-parser@1.20.2 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 23 | GHSA-rhx6-c78j-4q9w | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.12` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 56 | GHSA-869p-cjfg-cm3x | high | npm | `jws` | transitive / runtime | `3.2.2` | `3.2.3` | PGL | `jws@3.2.2 ← jsonwebtoken@9.0.2 ← universal-github-app-jwt@1.2.0 ← @octokit/auth-app@6.1.3 ← @octokit/app@14.1.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | +| 3 | GHSA-pwfr-8pq7-x9qv | high | npm | `octokit` | transitive / runtime | `3.1.1` | `3.1.2` | PGL | `octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | +| 11 | GHSA-9wv6-86v2-598j | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.10` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 13 | GHSA-qwcr-r2fm-qrc7 | high | npm | `body-parser` | transitive / runtime | `1.20.2` | `1.20.3` | PGL + WEBEXT + WPS | `body-parser@1.20.2 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 23 | GHSA-rhx6-c78j-4q9w | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.12` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 56 | GHSA-869p-cjfg-cm3x | high | npm | `jws` | transitive / runtime | `3.2.2` | `3.2.3` | PGL | `jws@3.2.2 ← jsonwebtoken@9.0.2 ← universal-github-app-jwt@1.2.0 ← @octokit/auth-app@6.1.3 ← @octokit/app@14.1.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | | 58 | GHSA-2w69-qvjg-hvjx | high | npm | `@remix-run/router` | transitive / runtime | `1.21.0` | `1.23.2` | ROUTER | `@remix-run/router@1.21.0 ← react-router-dom@6.28.0` | [#205](https://github.com/WordPress/try-wordpress/pull/205) | blocked; no published `react-router-dom` candidate removes this row without adding a current applicable advisory | -| 99 | GHSA-37ch-88jc-xwx2 | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.13` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 153 | GHSA-96hv-2xvq-fx4p | high | npm | `ws` | transitive / runtime | `8.18.0` | `8.21.0` | BLK + PGL + WEBEXT + WPS | `ws@8.18.0 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) + [#204](https://github.com/WordPress/try-wordpress/pull/204) | PGL, WEBEXT, and BLK paths are removed; vulnerable WPS paths remain | +| 99 | GHSA-37ch-88jc-xwx2 | high | npm | `path-to-regexp` | transitive / runtime | `0.1.7` | `0.1.13` | PGL + WEBEXT + WPS | `path-to-regexp@0.1.7 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 153 | GHSA-96hv-2xvq-fx4p | high | npm | `ws` | transitive / runtime | `8.18.0` | `8.21.0` | BLK + PGL + WEBEXT + WPS | `ws@8.18.0 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) + [#204](https://github.com/WordPress/try-wordpress/pull/204) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL, WEBEXT, and BLK paths are removed; vulnerable WPS paths remain | | 192 | GHSA-6g55-p6wh-862q | high | npm | `postcss` | transitive / runtime | `8.4.49` | `8.5.12` | BLK | `postcss@8.4.49 ← @wordpress/block-editor@14.2.0 ← @wordpress/block-library@9.12.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) | validated locally; vulnerable version absent globally | | 195 | GHSA-r28c-9q8g-f849 | high | npm | `postcss` | transitive / runtime | `8.4.49` | `8.5.18` | BLK | `postcss@8.4.49 ← @wordpress/block-editor@14.2.0 ← @wordpress/block-library@9.12.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) | validated locally; vulnerable version absent globally | | 6 | GHSA-3h5v-q93c-6h6q | high | npm | `ws` | transitive / development | `8.13.0` | `8.17.1` | WPS | `ws@8.13.0 ← puppeteer-core@20.9.0 ← lighthouse@10.4.0 ← @wordpress/e2e-test-utils-playwright@1.7.0 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable WPS path remains; integration branch documents upstream WPS residual | @@ -213,16 +213,16 @@ Rows are ordered by remediation priority: severity first, runtime before develop | 187 | GHSA-jr5f-v2jv-69x6 | high | npm | `axios` | transitive / development | `1.7.7` | `1.8.2` | WPS | `axios@1.7.7 ← wait-on@7.2.0 ← jest-dev-server@9.0.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | | 191 | GHSA-3jxr-9vmj-r5cp | high | npm | `brace-expansion` | transitive / development | `2.0.1` | `2.1.2` | WEBPACK + WPS | `brace-expansion@2.0.1 ← minimatch@5.1.6 ← readdir-glob@1.1.3 ← archiver@5.3.2 ← filemanager-webpack-plugin@8.0.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | incidental causal in-range refresh selects patched `brace-expansion@2.1.2`; vulnerable version absent globally in the integration branch | | 24 | GHSA-mwcw-c2x4-8c55 | medium | npm | `nanoid` | transitive / runtime | `3.3.7` | `3.3.8` | BLK | `nanoid@3.3.7 ← postcss@8.4.49 ← @wordpress/block-editor@14.2.0 ← @wordpress/block-library@9.12.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) | validated locally; vulnerable version absent globally | -| 29 | GHSA-x4c5-c7rf-jjgv | medium | npm | `@octokit/endpoint` | transitive / runtime | `9.0.5` | `9.0.6` | PGL | `@octokit/endpoint@9.0.5 ← @octokit/request@8.4.0 ← @octokit/core@5.2.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | -| 30 | GHSA-xx4v-prfh-6cgc | medium | npm | `@octokit/request-error` | transitive / runtime | `5.1.0` | `5.1.1` | PGL | `@octokit/request-error@5.1.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | -| 31 | GHSA-h5c3-5r3r-rr8q | medium | npm | `@octokit/plugin-paginate-rest` | transitive / runtime | `9.2.1` | `9.2.2` | PGL | `@octokit/plugin-paginate-rest@9.2.1 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | -| 32 | GHSA-rmvr-2pp2-xj38 | medium | npm | `@octokit/request` | transitive / runtime | `8.4.0` | `8.4.1` | PGL | `@octokit/request@8.4.0 ← @octokit/core@5.2.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201 | -| 57 | GHSA-6rw7-vpxm-498p | medium | npm | `qs` | transitive / runtime | `6.11.0` | `6.14.1` | PGL + WEBEXT + WPS | `qs@6.11.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 29 | GHSA-x4c5-c7rf-jjgv | medium | npm | `@octokit/endpoint` | transitive / runtime | `9.0.5` | `9.0.6` | PGL | `@octokit/endpoint@9.0.5 ← @octokit/request@8.4.0 ← @octokit/core@5.2.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | +| 30 | GHSA-xx4v-prfh-6cgc | medium | npm | `@octokit/request-error` | transitive / runtime | `5.1.0` | `5.1.1` | PGL | `@octokit/request-error@5.1.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | +| 31 | GHSA-h5c3-5r3r-rr8q | medium | npm | `@octokit/plugin-paginate-rest` | transitive / runtime | `9.2.1` | `9.2.2` | PGL | `@octokit/plugin-paginate-rest@9.2.1 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | +| 32 | GHSA-rmvr-2pp2-xj38 | medium | npm | `@octokit/request` | transitive / runtime | `8.4.0` | `8.4.1` | PGL | `@octokit/request@8.4.0 ← @octokit/core@5.2.0 ← octokit@3.1.1 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) | validated and merged into the integration branch by PR #201; resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range | +| 57 | GHSA-6rw7-vpxm-498p | medium | npm | `qs` | transitive / runtime | `6.11.0` | `6.14.1` | PGL + WEBEXT + WPS | `qs@6.11.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | | 59 | GHSA-9jcx-v3wj-wh4m | medium | npm | `react-router` | transitive / runtime | `6.28.0` | `6.30.2` | ROUTER | `react-router@6.28.0 ← react-router-dom@6.28.0` | [#205](https://github.com/WordPress/try-wordpress/pull/205) | blocked; no published `react-router-dom` candidate removes this row without adding a current applicable advisory | | 72 | GHSA-2g4f-4pwh-qvx6 | medium | npm | `ajv` | transitive / runtime | `8.12.0` | `8.18.0` | AJV + PGL + WEBEXT + WEBPACK + WPS | `ajv@8.12.0 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | web-ext `10.4.0` requires a compatible shared Ajv that resolves to patched `8.20.0`; vulnerable major-8 version absent globally in the integration branch | | 92 | GHSA-48c2-rrv3-qjmp | medium | npm | `yaml` | transitive / runtime | `1.10.2` | `1.10.3` | BLK | `yaml@1.10.2 ← cosmiconfig@7.1.0 ← babel-plugin-macros@3.1.0 ← @emotion/babel-plugin@11.12.0 ← @emotion/react@11.13.3 ← @wordpress/block-editor@14.2.0 ← @wordpress/block-library@9.12.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) + [#210](https://github.com/WordPress/try-wordpress/pull/210) | validated and merged into the integration branch by PR #210; obsolete types root removed and the shared compatible lock refreshed to patched `yaml@1.10.3`, so the vulnerable version is absent globally | | 113 | GHSA-rmmh-p597-ppvv | medium | npm | `showdown` | transitive / runtime | `1.9.1` | `none` | BLK | `showdown@1.9.1 ← @wordpress/blocks@13.10.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) | validated locally; vulnerable Showdown dependency absent globally | -| 132 | GHSA-58qx-3vcg-4xpx | medium | npm | `ws` | transitive / runtime | `8.18.0` | `8.20.1` | BLK + PGL + WEBEXT + WPS | `ws@8.18.0 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) + [#204](https://github.com/WordPress/try-wordpress/pull/204) | PGL, WEBEXT, and BLK paths are removed; vulnerable WPS paths remain | +| 132 | GHSA-58qx-3vcg-4xpx | medium | npm | `ws` | transitive / runtime | `8.18.0` | `8.20.1` | BLK + PGL + WEBEXT + WPS | `ws@8.18.0 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) + [#204](https://github.com/WordPress/try-wordpress/pull/204) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL, WEBEXT, and BLK paths are removed; vulnerable WPS paths remain | | 135 | GHSA-w5hq-g745-h8pq | medium | npm | `uuid` | transitive / runtime | `9.0.1` | `11.1.1` | BLK | `uuid@9.0.1 ← @wordpress/blocks@13.10.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) + [#209](https://github.com/WordPress/try-wordpress/pull/209) + [#210](https://github.com/WordPress/try-wordpress/pull/210) | root Blocks and direct Components paths patched; obsolete types root removed; the block-library path is blocked because its first patching candidate introduces an unsuppressed Firefox add-on security warning, and the affected WPS path also remains | | 139 | GHSA-2j2x-hqr9-3h42 | medium | npm | `react-router` | transitive / runtime | `6.28.0` | `6.30.4` | ROUTER | `react-router@6.28.0 ← react-router-dom@6.28.0` | [#205](https://github.com/WordPress/try-wordpress/pull/205) | blocked; no published `react-router-dom` candidate removes this row without adding a current applicable advisory | | 186 | GHSA-968p-4wvh-cqc8 | medium | npm | `@babel/runtime` | transitive / runtime | `7.25.6, 7.25.7` | `7.26.10` | BLK | `@babel/runtime@7.25.7 ← @wordpress/blocks@13.10.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) + [#209](https://github.com/WordPress/try-wordpress/pull/209) | root Blocks path patched; the remaining `@wordpress/block-library@9.27.0` path is blocked because every complete fixing candidate introduces an unsuppressed Firefox add-on security warning | @@ -236,7 +236,7 @@ Rows are ordered by remediation priority: severity first, runtime before develop | 52 | GHSA-mh29-5h37-fv8m | medium | npm | `js-yaml` | transitive / development | `4.1.0` | `4.1.1` | ESLINT-RESOLVER + WEBEXT + WPS | `js-yaml@4.1.0 ← eslint@8.57.1 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | causal in-range refresh selects patched `js-yaml@4.3.0`; vulnerable major-4 version absent globally in the integration branch | | 53 | GHSA-65ch-62r8-g69g | medium | npm | `node-forge` | transitive / development | `1.3.1` | `1.3.2` | WEBEXT + WPS | `node-forge@1.3.1 ← @devicefarmer/adbkit@3.2.6 ← web-ext@8.3.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | causal in-range refresh selects patched `node-forge@1.4.0`; vulnerable version absent globally in the integration branch | | 62 | GHSA-xxjr-mmjv-4gpg | medium | npm | `lodash` | transitive / development | `4.17.21` | `4.17.23` | CONCURRENTLY + WPS | `lodash@4.17.21 ← concurrently@9.1.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable CONCURRENTLY + WPS paths remain; integration branch documents upstream WPS residual | -| 101 | GHSA-3v7f-55p6-f55p | medium | npm | `picomatch` | transitive / development | `2.3.1` | `2.3.2` | ESLINT-RESOLVER + WEBPACK + WPS | `picomatch@2.3.1 ← micromatch@4.0.8 ← ts-loader@9.5.1` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable ESLINT-RESOLVER + WEBPACK + WPS paths remain; integration branch documents upstream WPS residual | +| 101 | GHSA-3v7f-55p6-f55p | medium | npm | `picomatch` | transitive / development | `2.3.1` | `2.3.2` | ESLINT-RESOLVER + WEBPACK + WPS | `picomatch@2.3.1 ← micromatch@4.0.8 ← ts-loader@9.5.1` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: vulnerable ESLINT-RESOLVER + WEBPACK + WPS paths remain; integration branch documents upstream WPS residual | | 102 | GHSA-f23m-r3pf-42rh | medium | npm | `lodash` | transitive / development | `4.17.21` | `4.18.0` | CONCURRENTLY + WPS | `lodash@4.17.21 ← concurrently@9.1.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable CONCURRENTLY + WPS paths remain; integration branch documents upstream WPS residual | | 108 | GHSA-r4q5-vmmm-2653 | medium | npm | `follow-redirects` | transitive / development | `1.15.9` | `1.16.0` | WPS | `follow-redirects@1.15.9 ← axios@1.7.7 ← wait-on@7.2.0 ← jest-dev-server@9.0.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | | 109 | GHSA-fvcv-3m26-pcqx | medium | npm | `axios` | transitive / development | `1.7.7` | `1.15.0` | WPS | `axios@1.7.7 ← wait-on@7.2.0 ← jest-dev-server@9.0.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | @@ -260,13 +260,13 @@ Rows are ordered by remediation priority: severity first, runtime before develop | 170 | GHSA-m28w-2pqf-7qgj | medium | npm | `webpack-dev-server` | transitive / development | `4.15.2` | `5.2.6` | WPS | `webpack-dev-server@4.15.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable WPS path remains; integration branch documents upstream WPS residual | | 179 | GHSA-mmx7-hfxf-jppx | medium | npm | `axios` | transitive / development | `1.7.7` | `1.18.0` | WPS | `axios@1.7.7 ← wait-on@7.2.0 ← jest-dev-server@9.0.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | | 180 | GHSA-7q8q-rj6j-mhjq | medium | npm | `axios` | transitive / development | `1.7.7` | `1.18.0` | WPS | `axios@1.7.7 ← wait-on@7.2.0 ← jest-dev-server@9.0.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | validated in the integration branch; vulnerable version absent globally | -| 15 | GHSA-qw6h-vgh9-j6wx | low | npm | `express` | transitive / runtime | `4.19.2` | `4.20.0` | PGL + WEBEXT + WPS | `express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 16 | GHSA-cm22-4g7w-348p | low | npm | `serve-static` | transitive / runtime | `1.15.0` | `1.16.0` | PGL + WEBEXT + WPS | `serve-static@1.15.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 17 | GHSA-m6fv-jmcg-4jfg | low | npm | `send` | transitive / runtime | `0.18.0` | `0.19.0` | PGL + WEBEXT + WPS | `send@0.18.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 18 | GHSA-pxg6-pf52-xh8x | low | npm | `cookie` | transitive / runtime | `0.6.0` | `0.7.0` | PGL + WEBEXT + WPS | `cookie@0.6.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 15 | GHSA-qw6h-vgh9-j6wx | low | npm | `express` | transitive / runtime | `4.19.2` | `4.20.0` | PGL + WEBEXT + WPS | `express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 16 | GHSA-cm22-4g7w-348p | low | npm | `serve-static` | transitive / runtime | `1.15.0` | `1.16.0` | PGL + WEBEXT + WPS | `serve-static@1.15.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 17 | GHSA-m6fv-jmcg-4jfg | low | npm | `send` | transitive / runtime | `0.18.0` | `0.19.0` | PGL + WEBEXT + WPS | `send@0.18.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 18 | GHSA-pxg6-pf52-xh8x | low | npm | `cookie` | transitive / runtime | `0.6.0` | `0.7.0` | PGL + WEBEXT + WPS | `cookie@0.6.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | | 64 | GHSA-73rr-hh4g-fpgx | low | npm | `diff` | transitive / runtime | `4.0.2` | `4.0.4` | BLK | `diff@4.0.2 ← @wordpress/block-editor@14.2.0 ← @wordpress/block-library@9.12.0` | [#204](https://github.com/WordPress/try-wordpress/pull/204) | validated locally; vulnerable version absent globally | -| 68 | GHSA-w7fw-mjwx-w883 | low | npm | `qs` | transitive / runtime | `6.11.0` | `6.14.2` | PGL + WEBEXT + WPS | `qs@6.11.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | -| 171 | GHSA-v422-hmwv-36x6 | low | npm | `body-parser` | transitive / runtime | `1.20.2` | `1.20.6` | PGL + WEBEXT + WPS | `body-parser@1.20.2 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | published PGL path removed by PR #201 but its bundled source remains upstream-blocked; WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 68 | GHSA-w7fw-mjwx-w883 | low | npm | `qs` | transitive / runtime | `6.11.0` | `6.14.2` | PGL + WEBEXT + WPS | `qs@6.11.0 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved in the final integration lock because no scope-matching installed version remains in the baseline advisory range; earlier child-stage evidence was: PGL path removed by PR #201 and WEBEXT path removed by web-ext `10.4.0`; vulnerable WPS path remains | +| 171 | GHSA-v422-hmwv-36x6 | low | npm | `body-parser` | transitive / runtime | `1.20.2` | `1.20.6` | PGL + WEBEXT + WPS | `body-parser@1.20.2 ← express@4.19.2 ← @php-wasm/web@1.0.13 ← @wp-playground/client@1.0.13` | [#201](https://github.com/WordPress/try-wordpress/pull/201) + [#202](https://github.com/WordPress/try-wordpress/pull/202) + [#203](https://github.com/WordPress/try-wordpress/pull/203) | resolved under the repository lock-path rule because no scope-matching installed version remains; non-scanner-visible PGL bundled-source risk remains upstream-blocked because official `@wp-playground/client` `3.1.38` through `3.1.47` source locks retain `body-parser@1.20.5` below the `1.20.6` patch | | 41 | GHSA-76c9-3jph-rj3q | low | npm | `on-headers` | transitive / development | `1.0.2` | `1.1.0` | WPS | `on-headers@1.0.2 ← compression@1.7.4 ← webpack-dev-server@4.15.2 ← @wordpress/scripts@30.4.0` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | vulnerable WPS path remains; integration branch documents upstream WPS residual | | 43 | GHSA-52f5-9888-hmc6 | low | npm | `tmp` | transitive / development | `0.2.3` | `0.2.4` | WEBEXT | `tmp@0.2.3 ← web-ext@8.3.0` | [#203](https://github.com/WordPress/try-wordpress/pull/203) | web-ext `10.4.0` selects patched `tmp@0.2.7`; vulnerable version absent globally in the integration branch | | 65 | GHSA-38r7-794h-5758 | low | npm | `webpack` | direct / development | `5.96.1` | `5.104.0` | WEBPACK | `webpack@5.96.1` | [#202](https://github.com/WordPress/try-wordpress/pull/202) | shared root webpack resolved to `5.109.0` to satisfy `@wordpress/scripts@30.7.0` requirement `^5.97.0`; vulnerable version absent globally; validated locally | @@ -309,9 +309,9 @@ No remote branch was deleted during baseline capture. Any later eligible deletio - `npm audit --json` exited 1 with 125 vulnerable/effect package keys and 143 unique npm GHSA references, while GitHub exposed 123 npm alert rows covering 116 unique npm GHSAs plus one Composer alert. These counts are not expected to match because npm audit reports the npm registry snapshot and propagates advisories through affected package/effect nodes, whereas the approved baseline is the GitHub repository alert-row set; no GitHub alert row was inferred from npm-only data. - The only baseline advisory with no first patched version is alert 113, `GHSA-rmmh-p597-ppvv` in `showdown`; its causal family remains BLK and remediation must remove the vulnerable dependency through that parent family. -### Child Execution Record: `agent/maintenance-002-playground-client` +### Child Execution Record: [#201](https://github.com/WordPress/try-wordpress/pull/201) -Status: validated and merged into the integration branch by child pull request [#201](https://github.com/WordPress/try-wordpress/pull/201). +Status: validated and merged into the integration branch by child pull request [#201](https://github.com/WordPress/try-wordpress/pull/201) at merge commit `9ec6eb7eb04d586815935a0e8258d5c016e3f2f4`. - Direct dependency change: `@wp-playground/client` moves from declared range `^1.0.13` and locked version `1.0.13` to declared range `^3.1.38` and locked version `3.1.38`. - Target alerts: 44, 3, 11, 13, 23, 56, 99, 153, 29, 30, 31, 32, 57, 72, 132, 15, 16, 17, 18, 68, and 171. @@ -327,7 +327,7 @@ Status: validated and merged into the integration branch by child pull request [ ### Child Execution Record: [#202](https://github.com/WordPress/try-wordpress/pull/202) -Status: validated and merged into the integration branch by child pull request [#202](https://github.com/WordPress/try-wordpress/pull/202). +Status: validated and merged into the integration branch by child pull request [#202](https://github.com/WordPress/try-wordpress/pull/202) at merge commit `8ae9ba695cacf83278549849d53ec19d58aa49ba`. - Direct dependency change: `@wordpress/scripts` moves from declared range `^30.4.0` and locked version `30.4.0` to declared range `^30.7.0` and locked version `30.7.0`; no other declared direct dependency changes. Root `package.json` continues to declare webpack `^5.96.1`, while the shared deduped `package-lock.json` resolution moves webpack from `5.96.1` to `5.109.0` because `@wordpress/scripts@30.7.0` requires webpack `^5.97.0`. - Semantic lock scope: the lockfile contains 78 installed version changes, 43 package paths added, and 44 package paths removed; only the declared direct dependency `@wordpress/scripts` changes. @@ -343,7 +343,7 @@ Status: validated and merged into the integration branch by child pull request [ ### Child Execution Record: [#203](https://github.com/WordPress/try-wordpress/pull/203) -Status: validated and merged into the integration branch by child pull request [#203](https://github.com/WordPress/try-wordpress/pull/203). +Status: validated and merged into the integration branch by child pull request [#203](https://github.com/WordPress/try-wordpress/pull/203) at merge commit `a0b204ca28a23c97dc4699dfe5f2dd55acf4d320`. - Direct dependency change: `web-ext` moves from declared range `^8.3.0` and locked version `8.3.0` to declared range `^10.4.0` and locked version `10.4.0`; no other declared direct dependency changes and no application, manifest, configuration, or npm-script changes. - Stable-release boundary evidence: registry manifests and clean isolated locks were examined for all nineteen stable releases newer than `8.3.0` through current `10.5.0`: `8.4.0`, `8.5.0`, `8.6.0`, `8.7.0`, `8.7.1`, `8.8.0`, `8.9.0`, `8.10.0`, `9.0.0`, `9.1.0`, `9.2.0`, `9.3.0`, `9.4.0`, `10.0.0`, `10.1.0`, `10.2.0`, `10.3.0`, `10.4.0`, and `10.5.0`. Every release through `10.3.0` pins `fx-runner@1.4.0` and affected `shell-quote@1.7.3`; `10.4.0` is the first stable release using `fx-runner@1.5.0` and critical-alert-patched `shell-quote@1.8.4`, so it is the minimum critical-remediation boundary. @@ -525,7 +525,7 @@ Status: validated and merged into the integration branch by child pull request [ ### Child Execution Record: [#217](https://github.com/WordPress/try-wordpress/pull/217) -Status: pre-action evidence was captured and linked in child pull request [#217](https://github.com/WordPress/try-wordpress/pull/217), which targets the integration branch, before the authorized external branch deletion completed. +Status: validated and merged into the integration branch by child pull request [#217](https://github.com/WordPress/try-wordpress/pull/217) at merge commit `6189aabbaeef452d4f84b9eabe879b984ba6b480`; its remote child branch was then deleted after the merge was verified. - Approved criterion: a live remote branch is eligible for deletion only when it has an associated pull request in any state or its exact tip is reachable from `origin/trunk`; an unmerged branch without an associated pull request must be preserved. - Reachability anchor: local `origin/trunk` is exactly `98f7c74d195d0b1ee95e4f9c16c7a9b527149980`, matching the approved pre-action anchor. @@ -552,5 +552,88 @@ Status: pre-action evidence was captured and linked in child pull request [#217] - Authoritative preserve set: `attempt-twitter`, `fix-test-wix`, and `npm_package_updates`. - Authoritative no-op set: `crawler`, which remains absent and retains the documented recovery references. - External deletion result: after PR #217 opened and the pre-action evidence was immediately reverified, the main maintenance workflow deleted exactly the ten authorized remote branches and no others. Remote-head deletion is external to source history; every removed branch remains recoverable from its exact pre-action SHA and associated PR or reachable trunk reference listed above. -- Post-action verification: both `git ls-remote --heads origin` and the paginated live branches API show all ten completed deletions absent, `crawler` still absent, and the preserved heads unchanged at `attempt-twitter` `09ea6328c0a7553328b1dddf78a2b35958e2fa15`, `fix-test-wix` `960f2d793bdf975e39c31304a296c168c0301aff`, and `npm_package_updates` `c9070d9d1bdd66ccf7a374d463b45c99e14e7683`. The active `trunk`, `agent/maintenance-security-and-hygiene`, and `agent/maintenance-018-stale-branch-triage` heads also remain present. -- Validation: the live remote and API branch sets are identical at six exact heads; the approved-plan-prefix SHA-256, 124-row baseline-alert count, Markdown table structure, and `git diff --check` pass. This documentation update performs no additional GitHub mutation. +- Post-action verification: both `git ls-remote --heads origin` and the paginated live branches API show all ten completed deletions absent, `crawler` still absent, and the preserved heads unchanged at `attempt-twitter` `09ea6328c0a7553328b1dddf78a2b35958e2fa15`, `fix-test-wix` `960f2d793bdf975e39c31304a296c168c0301aff`, and `npm_package_updates` `c9070d9d1bdd66ccf7a374d463b45c99e14e7683`. After PR #217 merged and its child branch was removed, the complete live remote set is exactly five heads: integration `agent/maintenance-security-and-hygiene` at `6189aabbaeef452d4f84b9eabe879b984ba6b480`, the three preserved branches at the SHAs above, and `trunk` at `98f7c74d195d0b1ee95e4f9c16c7a9b527149980`. +- Validation: the live remote and API branch sets are identical at five exact heads; the approved-plan-prefix SHA-256, 124-row baseline-alert count, Markdown table structure, and `git diff --check` pass. This documentation update performs no additional GitHub mutation. + +### Child Execution Record: [#218](https://github.com/WordPress/try-wordpress/pull/218) + +Status: final reconciliation is recorded by documentation-only child pull request [#218](https://github.com/WordPress/try-wordpress/pull/218), which targets the integration branch without changing dependency manifests, lockfiles, application source, configuration, generated schema, or license metadata. + +#### Child Pull Request Reconciliation + +Every maintenance child from the baseline capture through stale-branch triage is closed and merged into `agent/maintenance-security-and-hygiene`; the exact merge commits and canonical pull-request links are: + +| Child PR | Final state | Merge commit | +| --- | --- | --- | +| [#200](https://github.com/WordPress/try-wordpress/pull/200) | merged | `577ef6b1dbb6fce80f691a26767321fa7609b565` | +| [#201](https://github.com/WordPress/try-wordpress/pull/201) | merged | `9ec6eb7eb04d586815935a0e8258d5c016e3f2f4` | +| [#202](https://github.com/WordPress/try-wordpress/pull/202) | merged | `8ae9ba695cacf83278549849d53ec19d58aa49ba` | +| [#203](https://github.com/WordPress/try-wordpress/pull/203) | merged | `a0b204ca28a23c97dc4699dfe5f2dd55acf4d320` | +| [#204](https://github.com/WordPress/try-wordpress/pull/204) | merged | `dbb4421370d2e0acf04a6f7d8c2f984d56998d91` | +| [#205](https://github.com/WordPress/try-wordpress/pull/205) | merged | `0681a978c2c754a4f61f955a5b70992b24a7c330` | +| [#206](https://github.com/WordPress/try-wordpress/pull/206) | merged | `87f6889048add5a94c7026665cf47db4148f209b` | +| [#207](https://github.com/WordPress/try-wordpress/pull/207) | merged | `2409cfac0411e5270a457ced326b10fa472cf986` | +| [#208](https://github.com/WordPress/try-wordpress/pull/208) | merged | `1d0380b349c70ab2fb8d0581f8d294778d67e73f` | +| [#209](https://github.com/WordPress/try-wordpress/pull/209) | merged | `45ada19e2b2e72c9e79fa6c42e73842ae3907768` | +| [#210](https://github.com/WordPress/try-wordpress/pull/210) | merged | `c67167ea96768e02f6a0f484eb1df50a7962e15c` | +| [#211](https://github.com/WordPress/try-wordpress/pull/211) | merged | `0320cc54473c79014de3ad64c159860f3362de4a` | +| [#212](https://github.com/WordPress/try-wordpress/pull/212) | merged | `28972c9339f4f6e4389e12ce9bdf666d4cc613f6` | +| [#213](https://github.com/WordPress/try-wordpress/pull/213) | merged | `a3e940c1b0ef8c1d187cf581a71423c529344c91` | +| [#214](https://github.com/WordPress/try-wordpress/pull/214) | merged | `ac107e42eea15aa3082827696882367b40db606b` | +| [#215](https://github.com/WordPress/try-wordpress/pull/215) | merged | `862ac5d00d93d7632c2a91056330b81b49bda36c` | +| [#216](https://github.com/WordPress/try-wordpress/pull/216) | merged | `f8473294df0b45bc0afa10e580f238068063c24d` | +| [#217](https://github.com/WordPress/try-wordpress/pull/217) | merged | `6189aabbaeef452d4f84b9eabe879b984ba6b480` | + +#### Final Dependabot And Lockfile Reconciliation + +- Live default-branch state on 2026-07-28: the read-only GitHub Dependabot API still returns the original 124 open alerts with 124 unique alert numbers and returns zero dismissed alerts. The exact severity split remains 5 critical, 57 high, 48 medium, and 14 low; the ecosystem split remains 123 npm and one Composer. These results describe `trunk`, whose dependency manifests have not received draft integration PR #199, so GitHub's displayed alert state is expected to remain stale until that PR is merged and Dependabot recalculates the default branch. +- Integration-lock state: range-, scope-, and installed-path-aware comparison of every one of the 124 baseline rows finds 84 resolved rows and 40 residual rows. All five critical rows are resolved. The resolved split is 5 critical, 40 high, 28 medium, and 11 low; the residual split is 17 high, 20 medium, and 3 low. The Composer baseline row is resolved, so all 40 residual rows are npm rows. +- Row-level evidence: every baseline table row retains its baseline causal family, representative path, final child-PR link, and still-accurate historical status evidence; only statuses made stale by later child merges or lacking an explicit final resolution result are reconciled in place. A row is resolved only when no scope-matching installed package path remains in its GitHub advisory range. The final residual table below maps every residual alert to its complete current causal set and affected installed package versions. Aggregate npm-audit count reduction is not treated as resolution. +- Current causal roots for the 40 residual rows are `@wordpress/scripts@30.7.0`, `react-router-dom@6.28.0`, `@wordpress/block-library@9.27.0`, `web-ext@10.4.0`, `@babel/preset-env@7.26.0`, and `concurrently@9.1.0`. Version-qualified `npm explain` completed successfully for every distinct residual package/version pair and found no unmapped path. + +| Current residual causal set | Affected installed package version(s) | Count | Baseline alert numbers | +| --- | --- | ---: | --- | +| WPS | `@tootallnate/once@2.0.0`, `http-proxy-middleware@2.0.6`, `ip-address@9.0.5`, `launch-editor@2.9.1`, `linkify-it@3.0.3`, `markdown-it@12.3.2`, `minimatch@3.0.8`, `minimatch@9.0.3`, `on-headers@1.0.2`, `playwright@1.48.2`, `serialize-javascript@6.0.2`, `svgo@3.3.2`, `tar-fs@3.0.4`, `webpack-dev-server@4.15.2`, `ws@7.5.10`, `ws@8.13.0` | 26 | 6, 33, 36, 37, 38, 39, 41, 46, 49, 79, 83, 84, 85, 115, 131, 133, 134, 151, 152, 154, 158, 160, 169, 170, 172, 173 | +| ROUTER | `@remix-run/router@1.21.0`, `react-router@6.28.0` | 5 | 58, 59, 139, 193, 194 | +| CONCURRENTLY + WPS | `lodash@4.17.21` | 3 | 62, 102, 103 | +| BLK | `@babel/runtime@7.25.7`, `uuid@9.0.1` | 2 | 135, 186 | +| BABEL + WPS | `@babel/core@7.25.7`, `@babel/plugin-transform-modules-systemjs@7.25.9` | 2 | 127, 159 | +| WEBEXT | `shell-quote@1.8.4` | 1 | 167 | +| WEBEXT + WPS | `adm-zip@0.5.16` | 1 | 166 | +| **Total** | **23 distinct package names across 25 package/version pairs** | **40** | **40 unique baseline alert numbers** | + +- Blocker boundaries: the ROUTER rows require the documented React Router major migration or would add a current applicable advisory; the BLK rows remain behind a block-library candidate that adds an unsuppressed Firefox add-on security warning and materially expands the startup bundle; the WPS-related rows remain in published scripts tooling or tightly coupled roots whose tested next boundaries either retain affected paths, add a new applicable advisory, or require a broad ESLint/application migration. The WEBEXT residual is in its current locked linter path. These boundaries remain explicit blockers and were not bypassed with an override, downgrade, advisory dismissal, additional ignored Firefox file, or silent broad migration. + +#### npm Audit Advisories Outside The Baseline + +The final Node 24 clean install reports 111 npm audit effect-package keys: 87 high, 15 moderate, 9 low, and zero critical, covering 60 unique GHSAs. Seven applicable audit GHSAs are absent from both the 124-row baseline and the still-identical live default-branch alert set, so no GitHub alert number can truthfully be assigned yet: + +| GHSA | Severity | Affected installed package version(s) | Current causal family set | +| --- | --- | --- | --- | +| GHSA-22p9-wv53-3rq4 | high | `linkify-it@3.0.3` | WPS | +| GHSA-23c5-xmqv-rm74 | high | `minimatch@3.0.8`, `minimatch@9.0.3` | WPS | +| GHSA-3ppc-4f35-3m26 | high | `minimatch@3.0.8`, `minimatch@9.0.3` | WPS | +| GHSA-9gqv-wp59-fq42 | moderate | `http-proxy-middleware@2.0.6` | WPS | +| GHSA-c2c7-rcm5-vvqj | high | `picomatch@2.3.1` | ESLINT-RESOLVER + WEBPACK + WPS | +| GHSA-c7qv-q95q-8v27 | high | `http-proxy-middleware@2.0.6` | WPS | +| GHSA-mh99-v99m-4gvg | high | `brace-expansion@1.1.16`, `brace-expansion@2.1.2` | ESLINT-RESOLVER + WEBEXT + WEBPACK + WPS | + +These are six high and one moderate advisory. Version-qualified `npm explain` confirms that GHSA-mh99-v99m-4gvg reaches `brace-expansion@1.1.16` through WEBEXT, WPS, ESLINT-RESOLVER, and the filemanager-webpack-plugin member of WEBPACK, while `brace-expansion@2.1.2` reaches the root through WPS and filemanager-webpack-plugin. They are locally applicable findings requiring follow-up causal remediation and reconciliation with any GitHub alert numbers created after the default branch changes; their absence from today's default-branch API response is not a dismissal or resolution. + +#### Final Automated Validation And Handoff + +- Local Node validation: Node `v24.18.0` with npm `11.16.0` completed a clean `npm ci`, schema-aware `npm run type-check`, `npm run lint`, and sequential `npm run build:production:firefox` and `npm run build:production:chrome`. Both builds succeeded with only the documented Playground dynamic-request and asset-size warnings and retained the approximately 21.2 MiB `app.js` plus `498.app.js`, `300.app.js`, and `717.app.js`. +- Packaged-extension validation: `npm run validate:extension-builds` validated all nine script, page, and icon references in each production target. `npm run lint:extension:firefox` ignored only generated `app.js`, returned zero errors and notices, and returned the single allowed `UNSUPPORTED_API` warning at `background.js:1:77`. +- Audit and path validation: `npm audit --json` returned the nonzero 111-effect result documented above. Exact advisory-range checks over all lock paths produced the 84/40 baseline classification, and version-qualified `npm explain` assertions passed for all residual versions. The nonzero audit and 40 baseline residuals mean final automated security acceptance is blocked rather than complete. +- Composer and PHP validation: an official Composer 2 container completed `composer audit --locked --no-interaction` against the final lock with no advisory. The exact PR #217 head `0cf0af5bccd09ddb337c7960a2f51948444d308d` completed hosted `PHPCS PHP 8.3`, `PHPCS PHP 8.4`, `PHPUnit 8.3`, and `PHPUnit 8.4` jobs successfully; each PHPUnit matrix job performed a clean locked Composer install, the same locked audit, Node 24 `npm ci`, deterministic schema generation, latest-stable WordPress resolution and test-library installation, and the complete PHPUnit suite. The browser lint job on that same head also passed. Child pull request [#218](https://github.com/WordPress/try-wordpress/pull/218) and integration PR #199 hosted checks remain the authoritative final gates after this documentation change. +- Integrity and scope: SHA-256 comparison before and after local validation proves `package.json`, `package-lock.json`, `composer.json`, and `composer.lock` are byte-identical. This child changes only `plan.md`; it adds no npm override, Composer replacement, downgrade, alert dismissal, public API change, stored-data schema change, generated schema change, application behavior change, or license/license-metadata change. +- Integration state: draft integration pull request [#199](https://github.com/WordPress/try-wordpress/pull/199) remains open, draft, and unmerged for user testing. It must not be marked ready or merged merely because the automated functional gates pass; the residual baseline and new audit advisories above require an explicit remediation or risk decision first. + +Manual handoff checklist: + +- Load `build/production/firefox` and `build/production/chrome` as unpacked extensions and verify the Firefox sidebar and Chrome side panel open without browser-console errors. +- Start WordPress Playground in both targets, confirm the emitted Playground/vendor asynchronous bundle is requested successfully at runtime, and compare startup, parse, and memory behavior against the documented approximately 21.2 MiB startup bundle risk. +- Import representative site navigation and multiple representative pages, preview the imported content, and confirm content, links, media, and layout behave as expected. +- Reload and close/reopen each browser session, verify session persistence, then inspect both browser-extension logs and WordPress/PHP logs for warnings, uncaught errors, failed requests, and missing chunks. +- Exercise both Firefox and Chrome development watch/start commands, change a copied manifest/icon/plugin/schema input, and verify one correct rebuild and recopy without an output-triggered watch loop. +- Reconfirm the provisional Firefox Gecko ID and declared data-collection categories before first publication, the single allowed Firefox unsupported-API warning, and the absence of any additional manifest or generated-bundle lint diagnostic.