Skip to content

Track existing dependency advisories separately from Model Core integration #186

Description

@KillerQueen-Z

Problem

An authorized npm audit of Franklin commit 6c0a900a60ab75aaeebaaf8f78dca8ac74e73ead reports 36 affected-package entries: 11 high, 8 moderate, 17 low, and 0 critical. Counts include dependency-chain propagation; these are version matches, not 36 independently validated exploit paths.

Compared the exact Model Core integration range (f60038e41bd71ecca43dbb9aee951784ce8420a0 → 4dad775dfbc822ee8174c00d3207c1eb947afc69, PR #181): all affected package paths already existed at the same versions. The sole added package was @blockrun/model-catalog, with no runtime dependencies. Track this as existing dependency maintenance, separately from the catalog feature.

Priorities

  • sharp 0.35.3: upgrade to at least the patched 0.35.4 and verify image reading/resizing. Maintainer advisory.
  • axios 1.18.1: review the audit-reported patches (1.20.0+) and run Polymarket HTTP/auth regressions. Example advisory.
  • bigint-buffer 1.1.5 through Solana dependencies: evaluate upstream replacement/remediation; audit reports no automatic fix. Advisory.
  • undici 7.29.0 / development 6.28.0, fast-uri 3.1.6: update affected packages and check consumer compatibility. The npm undici package is distinct from Node's bundled fetch implementation.
  • brace-expansion and js-yaml: affected lockfile paths are development dependencies; update with desktop/build regression checks.

Acceptance criteria

  • Record each advisory as fixed, not reachable with documented evidence, or explicitly deferred with an owner/reason.
  • Run npm audit again and report remaining entries without conflating transitive duplicates with distinct vulnerabilities.
  • Run Franklin local tests, image-path tests, applicable Solana/payment and Polymarket regressions, and desktop builds after dependency changes.
  • Keep this work separate from Model Core behavior changes; do not apply a blanket npm audit fix --force.

No exploit or production compromise has been demonstrated by this version audit. This issue contains public dependency/advisory information only.

Activity

  1. added a commit that references this issue on Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions