mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
chore(deps): clear every npm audit and pip-audit finding
Frontend: - react-router/-dom 7.18.1 -> 7.18.2. The RSC-mode CSRF advisory was carried as a documented exception in the audit gate because its only fix was the 8.3.0 major; upstream backported it, so the exemption lapsed on its own -- an entry only holds while fixAvailable.isSemVerMajor is true. The allowlist is now empty; the machinery stays for the next one. - dompurify 3.4.12 -> 3.4.13. Ships in the app, but the path is unreachable: no hooks registered, IN_PLACE never used. - js-yaml override ^4.3.0 -> ^5.2.3 (fix not backported below 5.x, so a major) and nanoid override ^3.3.18. Both dev-only, via eslint and postcss. eslintrc calls only load(), on the legacy .eslintrc.yml path this repo does not use; eslint, vite build and 2861 frontend tests pass on it. Backend: - cryptography >=48.0.1 -> >=50.0.0, aiohttp >=3.14.0 -> >=3.14.3, pyopenssl >=26.3.0 -> >=26.4.0. CI resolves from scratch and was already installing the fixed releases; the floors cover the case CI does not, an existing venv where >= is satisfied and `pip install -r` upgrades nothing. pyOpenSSL has to move with cryptography -- each release caps it to a narrow window, so a stale pyOpenSSL pins cryptography below its own fix line.
This commit is contained in:
@@ -203,15 +203,12 @@ jobs:
|
||||
vulns = data.get('vulnerabilities', {})
|
||||
# Documented advisory exceptions: high/critical findings whose only offered
|
||||
# 'fix' is a semver-major change and which do not apply to how Bambuddy ships.
|
||||
# Keyed by GHSA id; RE-REVIEW ON EVERY react-router BUMP.
|
||||
# GHSA-qwww-vcr4-c8h2 - React Router RSC-mode CSRF. Bambuddy is a Vite SPA
|
||||
# using BrowserRouter with no RSC runtime (@react-router/server is NOT
|
||||
# installed), so the vulnerable code path is unreachable. No non-major fix
|
||||
# exists (7.18.1 is the most-patched 7.x - it clears 14 other advisories that
|
||||
# older 7.x carry - and the RSC fix landed only in the 8.3.0 major). react-router
|
||||
# /-dom are pinned to 7.18.1 in package.json. If a non-major fix ships, this stops
|
||||
# being exempt (major-only guard below) and the gate fails until we take it.
|
||||
ALLOWLIST = {'GHSA-qwww-vcr4-c8h2'}
|
||||
# Keyed by GHSA id. An entry only holds while the fix stays major-only (see
|
||||
# fix_is_major below) - once upstream backports, the gate fails until we take
|
||||
# the patch. That is what retired the one entry this list used to carry:
|
||||
# GHSA-qwww-vcr4-c8h2 (React Router RSC-mode CSRF) shipped in 7.18.2, so the
|
||||
# pin moved rather than the exception staying.
|
||||
ALLOWLIST = set()
|
||||
def advisory_ids(name, seen=None):
|
||||
seen = seen if seen is not None else set()
|
||||
if name in seen:
|
||||
|
||||
Reference in New Issue
Block a user