chore(deps): clear every npm audit and pip-audit finding

Frontend:
- react-router/-dom 7.18.1 -> 7.18.2. The RSC-mode CSRF advisory was carried
  as a documented exception in the audit gate because its only fix was the
  8.3.0 major; upstream backported it, so the exemption lapsed on its own --
  an entry only holds while fixAvailable.isSemVerMajor is true. The allowlist
  is now empty; the machinery stays for the next one.
- dompurify 3.4.12 -> 3.4.13. Ships in the app, but the path is unreachable:
  no hooks registered, IN_PLACE never used.
- js-yaml override ^4.3.0 -> ^5.2.3 (fix not backported below 5.x, so a
  major) and nanoid override ^3.3.18. Both dev-only, via eslint and postcss.
  eslintrc calls only load(), on the legacy .eslintrc.yml path this repo does
  not use; eslint, vite build and 2861 frontend tests pass on it.

Backend:
- cryptography >=48.0.1 -> >=50.0.0, aiohttp >=3.14.0 -> >=3.14.3, pyopenssl
  >=26.3.0 -> >=26.4.0. CI resolves from scratch and was already installing
  the fixed releases; the floors cover the case CI does not, an existing venv
  where >= is satisfied and `pip install -r` upgrades nothing. pyOpenSSL has
  to move with cryptography -- each release caps it to a narrow window, so a
  stale pyOpenSSL pins cryptography below its own fix line.
This commit is contained in:
maziggy
2026-08-08 13:20:18 +02:00
parent 73eec29358
commit c8e5ecc23a
7 changed files with 54 additions and 52 deletions
+6 -9
View File
@@ -203,15 +203,12 @@ jobs:
vulns = data.get('vulnerabilities', {})
# Documented advisory exceptions: high/critical findings whose only offered
# 'fix' is a semver-major change and which do not apply to how Bambuddy ships.
# Keyed by GHSA id; RE-REVIEW ON EVERY react-router BUMP.
# GHSA-qwww-vcr4-c8h2 - React Router RSC-mode CSRF. Bambuddy is a Vite SPA
# using BrowserRouter with no RSC runtime (@react-router/server is NOT
# installed), so the vulnerable code path is unreachable. No non-major fix
# exists (7.18.1 is the most-patched 7.x - it clears 14 other advisories that
# older 7.x carry - and the RSC fix landed only in the 8.3.0 major). react-router
# /-dom are pinned to 7.18.1 in package.json. If a non-major fix ships, this stops
# being exempt (major-only guard below) and the gate fails until we take it.
ALLOWLIST = {'GHSA-qwww-vcr4-c8h2'}
# Keyed by GHSA id. An entry only holds while the fix stays major-only (see
# fix_is_major below) - once upstream backports, the gate fails until we take
# the patch. That is what retired the one entry this list used to carry:
# GHSA-qwww-vcr4-c8h2 (React Router RSC-mode CSRF) shipped in 7.18.2, so the
# pin moved rather than the exception staying.
ALLOWLIST = set()
def advisory_ids(name, seen=None):
seen = seen if seen is not None else set()
if name in seen: