Skip to content

Clear the five npm advisories (lockfile only) — closes #34 - #35

Merged
ethanplusai merged 1 commit into
mainfrom
chore/npm-audit-fix
Sep 7, 2026
Merged

ethanplusai merged 1 commit into
mainfrom
chore/npm-audit-fix

Conversation

@ethanplusai

Copy link
Copy Markdown
Owner

Closes #34.

npm audit fix takes all five advisories to patched releases inside the ranges package.json already declares, so only the lockfile moves — 16 insertions, 17 deletions, no dependency ranges changed:

package severity
fflate 0.8.2 → 0.8.3 moderate — reported in #34
nanoid → 3.3.18 high
picomatch → 4.0.7 high
postcss → 8.5.28 high
vite 6.4.1 → 6.4.3 high

npm audit now reports 0 vulnerabilities.

On #34 specifically

The advisory is real and worth taking, but it is not reachable in this project:

  • fflate arrives transitively through @types/three
  • its code does not appear in the built bundle (checked dist/assets/*.js)
  • nothing in src/ imports it, and JARVIS never opens an archive — let alone one it did not write itself

Two details in the report don't hold up: npm rates this moderate, not high; and the four genuinely high advisories sitting in the same dependency tree weren't mentioned. Taking the bump regardless — it's free, and an audit that is noisy is an audit nobody reads.

Also not the patch the issue proposes. That diff edits node_modules/fflate/dist/unzip.js, which isn't version controlled — the next npm ci throws it away.

Testing

Typecheck clean, npm run build clean, dev server boots and serves (Vite 6.4.3), 2405 Python tests pass.

Branched off main, independent of #32 and #33.

🤖 Generated with Claude Code

`npm audit fix` takes all five to patched releases inside the ranges
package.json already declares, so only the lockfile moves:

    fflate     0.8.2  -> 0.8.3    (moderate)  reported as #34
    nanoid     3.3.x  -> 3.3.18   (high)
    picomatch  4.0.x  -> 4.0.7    (high)
    postcss    8.5.x  -> 8.5.28   (high)
    vite       6.4.1  -> 6.4.3    (high)

On #34 specifically: the advisory is real, and worth taking, but it is not
reachable here. `fflate` arrives through `@types/three`, its code does not
appear in the built bundle, and nothing in `src/` imports it or unzips
anything — JARVIS never opens an archive, let alone one it did not write.
npm rates it moderate rather than high, and the four genuinely high
advisories in the same tree were not the ones reported. Taking the bump
anyway: it is free, and an audit that is noisy is an audit nobody reads.

Not the patch the issue suggests. That one edits `node_modules/fflate/`,
which is not version controlled — the next `npm ci` discards it.

Typecheck clean, build clean, dev server serves, 2405 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@ethanplusai
ethanplusai merged commit 16e37bd into main Sep 7, 2026
2 checks passed
DavidN0809 pushed a commit to Nichols-HomeLab/jarvis that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant