Skip to content

fix(deps): eliminate npm audit vulnerabilities - #5959

Closed
Sun-GLiang wants to merge 1 commit into
apache:mainfrom
Sun-GLiang:codex/fix-npm-audit-vulnerabilities
Closed

Sun-GLiang wants to merge 1 commit into
apache:mainfrom
Sun-GLiang:codex/fix-npm-audit-vulnerabilities

Conversation

@Sun-GLiang

Copy link
Copy Markdown
Member

Summary

npm ci reported eight vulnerable dependency entries (one low, seven high). A clean install and full npm audit now report found 0 vulnerabilities.

  • Upgrade Electron to 43.5.0, devalue to 5.9.4, DOMPurify to 3.4.16, and http-cache-semantics to 4.3.0; refresh the Desktop license inventory.
  • Keep patch-package 8.0.1, but replace its workspace-root helper with a repository-owned synchronous adapter using picomatch. This removes the remaining micromatch/braces dependency chain; braces has no published fix for GHSA-vfj7-8cjw-p6xm. Document when to remove the override.
  • Cover workspace discovery, ordered exclusions, nested workspace boundaries, deeply nested brace patterns, and the installed override in CI after dependency installation.

Verification

  • Clean npm ci and npm audit: 0 vulnerabilities, all 14 existing patches applied successfully.
  • Adapter and CI workflow tests: 55 passed.
  • Mermaid rendering/export tests and website build/tests: 39 passed, with Mermaid tests rerun against freshly built output.
  • Temporary-project smoke test: patch-package generated a patch, applied it to a clean package, and reapplied it idempotently.
  • npm run lint, npm run format:check, npm run build, npm run typecheck: passed.
  • npx knip --workspace apps/desktop and npx knip --workspace packages/ui: passed.
  • Desktop/CLI third-party notice checks, npm ls find-yarn-workspace-root --all, and git diff --check: passed.
  • Full workspace test suite and interactive Desktop/Electron regression testing were not run. Electron's runtime version was verified as 43.5.0.

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: OpenAI Codex investigated the dependency advisories, authored the dependency updates and workspace-root adapter/tests, ran verification, and prepared this draft PR. The commit includes a Generated-by: OpenAI Codex trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No

Upgrade Electron, devalue, DOMPurify and http-cache-semantics to fixed
versions. Replace patch-package's workspace-root helper with a local
picomatch-based adapter to remove the unpatched micromatch/braces chain.

Keep patch-package's patch creation and application behavior, cover the
adapter in CI, and refresh the Desktop dependency license inventory.

Generated-by: OpenAI Codex
@github-actions github-actions Bot added the effort/M Under 500 readable lines label Oct 4, 2026
@Sun-GLiang Sun-GLiang closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/M Under 500 readable lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant