Skip to content

fix(deps): patch the dependency advisories from #186 - #194

Merged
VickyXAI merged 1 commit into
mainfrom
fix/dependency-advisories
Oct 3, 2026
Merged

VickyXAI merged 1 commit into
mainfrom
fix/dependency-advisories

Conversation

@VickyXAI

@VickyXAI VickyXAI commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #186. This only changes dependencies; no Model Core or other behavior changes. No npm audit fix --force and no major bumps.

Fixed

Advisory Was Now How
sharp (libheif, GHSA-rgj7-g3m4-5g8c) 0.35.3 0.35.5 direct bump
axios (12 advisories) 1.18.1 1.20.0 direct bump, plus the override for @polymarket/builder-relayer-client
undici 7.29.0 / 6.28.0 (dev) 7.30.0 / 6.29.0 in-range update
fast-uri 3.1.6 3.1.8 in-range update
js-yaml (dev) 4.3.1 4.3.2 in-range update
brace-expansion (dev) 1.1.18 / 2.1.4 / 5.0.9 1.1.21 / 2.1.7 / 5.0.12 in-range update
hono 4.13.4 4.13.12 in-range update
ip-address 10.5.0 10.7.3 in-range update

@solana/web3.js intentionally stays at 1.98.4. A plain npm audit fix would move it to 1.99, which fixes no advisory and swaps the Solana signer's codecs-numbers from 2.x to 5.x.

Remaining: no upstream fix; reachability evidence or deferral

Advisory Path Status
bigint-buffer ≤1.1.5 (GHSA-3gc7-fjrx-p6mg), high spl-token → buffer-layout-utils Not reachable. The only caller decodes a fixed-length blob(length) layout and always passes a Buffer of that size; the overflow needs malformed input. Deferred until upstream replaces it. Owner: Franklin maintainers.
braces ≤3.0.3, high desktop devDep shadcn → fast-glob → micromatch Not shipped. A dev-time CLI with globs we write ourselves. Deferred to a shadcn release.
http-cache-semantics ≤4.2.0, high desktop devDep electron-builder → @electron/get → got Build time only. It downloads Electron binaries with no shared multi-user cache. Deferred until electron-builder drops got 11.
elliptic ≤6.6.1, low @polymarket/builder-relayer-client → ethers 5 Deferred. It sits in the upstream SDK, and the Polymarket port must stay byte-faithful to upstream. Revisit when the relayer client moves off ethers 5.
stream-json ≤3.4.0, moderate @solana/web3.js → jayson Not reachable. The advisory is in the pick/ignore/filter/replace filters. jayson only uses StreamValues and Verifier, and only in utils.parseStream, its server-side request parser, which the web3.js RPC client never calls.
uuid <11.1.1, moderate @solana/web3.js → jayson Not reachable. jayson only calls v4 without a buf argument; the bug is in v3/v5/v6 with buf.

npm audit: 50 entries (25 high) before, 42 entries (19 high) after. The 42 are those six roots plus the packages that depend on them.

Verification

  • npm test: 791 pass, including the Polymarket, Solana-migration and api-key suites.
  • Image path: the Read tool on a 4000×3000 PNG resizes through sharp 0.35.5 (libvips 8.18.7).
  • Polymarket HTTP: a live fetchPositions call on axios 1.20.0 returns data.
  • Desktop: npm run build succeeds, and npm test passes (39 vitest, 6 security, cloud and team-proxy).

🤖 Generated with Claude Code

…sion, hono, ip-address (#186)

Direct: sharp 0.35.3 -> 0.35.5 (libheif advisories), axios 1.18.1 -> 1.20.0,
including the copy pinned under @polymarket/builder-relayer-client. In-range
transitive updates via targeted `npm update` (no `audit fix --force`, no
major bumps): undici 7.30.0 / 6.29.0, fast-uri 3.1.8, js-yaml 4.3.2,
brace-expansion 1.1.21 / 2.1.7 / 5.0.12, hono 4.13.12, ip-address 10.7.3.
@solana/web3.js deliberately stays at 1.98.4: 1.99 fixes no advisory and
changes the Solana signer's codec dependency.

npm audit: 50 entries (25 high) -> 42 (19 high), six root advisories left,
none with an upstream fix; reachability recorded on the issue.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@VickyXAI
VickyXAI merged commit 1ec72f3 into main Oct 3, 2026
6 checks passed
@VickyXAI
VickyXAI deleted the fix/dependency-advisories branch October 3, 2026 02:18
@VickyXAI VickyXAI mentioned this pull request Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Track existing dependency advisories separately from Model Core integration

1 participant