Problem
An authorized npm audit of Franklin commit 6c0a900a60ab75aaeebaaf8f78dca8ac74e73ead reports 36 affected-package entries: 11 high, 8 moderate, 17 low, and 0 critical. Counts include dependency-chain propagation; these are version matches, not 36 independently validated exploit paths.
Compared the exact Model Core integration range (f60038e41bd71ecca43dbb9aee951784ce8420a0 → 4dad775dfbc822ee8174c00d3207c1eb947afc69, PR #181): all affected package paths already existed at the same versions. The sole added package was @blockrun/model-catalog, with no runtime dependencies. Track this as existing dependency maintenance, separately from the catalog feature.
Priorities
- sharp 0.35.3: upgrade to at least the patched 0.35.4 and verify image reading/resizing. Maintainer advisory.
- axios 1.18.1: review the audit-reported patches (1.20.0+) and run Polymarket HTTP/auth regressions. Example advisory.
- bigint-buffer 1.1.5 through Solana dependencies: evaluate upstream replacement/remediation; audit reports no automatic fix. Advisory.
- undici 7.29.0 / development 6.28.0, fast-uri 3.1.6: update affected packages and check consumer compatibility. The npm undici package is distinct from Node's bundled fetch implementation.
- brace-expansion and js-yaml: affected lockfile paths are development dependencies; update with desktop/build regression checks.
Acceptance criteria
- Record each advisory as fixed, not reachable with documented evidence, or explicitly deferred with an owner/reason.
- Run npm audit again and report remaining entries without conflating transitive duplicates with distinct vulnerabilities.
- Run Franklin local tests, image-path tests, applicable Solana/payment and Polymarket regressions, and desktop builds after dependency changes.
- Keep this work separate from Model Core behavior changes; do not apply a blanket
npm audit fix --force.
No exploit or production compromise has been demonstrated by this version audit. This issue contains public dependency/advisory information only.
Problem
An authorized
npm auditof Franklin commit6c0a900a60ab75aaeebaaf8f78dca8ac74e73eadreports 36 affected-package entries: 11 high, 8 moderate, 17 low, and 0 critical. Counts include dependency-chain propagation; these are version matches, not 36 independently validated exploit paths.Compared the exact Model Core integration range (
f60038e41bd71ecca43dbb9aee951784ce8420a0→4dad775dfbc822ee8174c00d3207c1eb947afc69, PR #181): all affected package paths already existed at the same versions. The sole added package was@blockrun/model-catalog, with no runtime dependencies. Track this as existing dependency maintenance, separately from the catalog feature.Priorities
Acceptance criteria
npm audit fix --force.No exploit or production compromise has been demonstrated by this version audit. This issue contains public dependency/advisory information only.