Repository navigation
fix(deps): resolve brace-expansion, http-cache-semantics and serialize-javascript Snyk/npm-audit findings (+Claude) - #238
Conversation
…e-javascript Snyk/npm-audit findings (+Claude) Raise the brace-expansion override floors to the patched releases (^5.0.12, ^2.1.7, ^1.1.21) for SNYK-JS-BRACEEXPANSION-20244948, -20244950 and -20244952, and refresh http-cache-semantics (4.3.0) and serialize-javascript (7.1.2) in the lockfile. Retire the ajv, fast-uri, proxy-addr and istanbul-lib-processinfo overrides, which no longer change what the tree resolves. #claude_code# 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The targeted manifest and lockfile changes are consistent, with no blocking issues identified and passing validation reported.
Review effort: Balanced
Findings: None
What changed in this PR
Addresses dependency security advisories in the Launch CLI without changing application code.
Changes:
- Raises brace-expansion override floors to patched releases.
- Updates http-cache-semantics and serialize-javascript in the lockfile.
- Removes obsolete overrides while retaining those still needed.
| File | Description |
|---|---|
| package.json | Raises security override floors and removes obsolete overrides. |
| package-lock.json | Records patched dependencies and updated placement of nested packages. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
What changed
Automated snyk-fix run (05-Oct-2026), Node surface only (
launch-clihas onepackage.json, no Go, no Dockerfile). Based ondevelopment.Fixes
@oclif/core > minimatch@10.2.5)minimatch@10.2.5override floor raised^5.0.9->^5.0.12minimatch@9.0.9,minimatch@5.1.9floors^2.1.4->^2.1.7;brace-expansion@1floor^1.1.18->^1.1.21, so a fresh install cannot resolve a vulnerable releaseoclif > got > cacheable-request)npm audit, not by Snykmocha)^7.1.0overrideAll ranges are carets (loosest safe floor).
Ecosystem-native audit (step 1.5)
npm audit: 43 (1 low, 5 moderate, 37 high) -> 40 (5 moderate, 35 high) after this PR. The remainder is documented under "needs human review".npm audit fix(no--force) was run first. It resolved the advisories above but also bumped@oclif/core4.11.14 -> 4.14.0,@contentstack/cli-command/cli-utilities,oclif,@oclif/plugin-not-foundandplugin-warn-if-update-available, none of which carried an advisory.@oclif/core@4.14.0makes all 6 suites ofnpm run test:integrationfail (A dynamic import callback was invoked without --experimental-vm-modules), reproduced on a cleanorigin/developmentcheckout with only that package bumped. Those unrelated bumps were therefore discarded and only the advisory-backed ones kept (http-cache-semantics, serialize-javascript, brace-expansion), applied by targetednpm updateplus the override edits.braces<=3.0.3 (GHSA-vfj7-8cjw-p6xm, high, no patched 3.x exists) reached viamicromatchfromlint-staged,jest,oclif,shx(all devDependencies); npm's only offered fix is a major bump of those tools.Retired overrides (step 2.5)
Removed from
package.jsonoverrides:ajv,fast-uri,proxy-addr,istanbul-lib-processinfo.uuid. Evidence: with each removed, a fresh resolve and the real tree still land at or above the old floor on their own (ajv@8.20.0viaconf,fast-uri@3.1.8viaajv,proxy-addr@2.0.8viaexpress), andistanbul-lib-processinfo@3.0.1no longer depends onuuidat all.npm lsand the Snyk re-scan are clean for these. Theqsoverride was also tested and is NOT obsolete:express@4.22.2pinsqs ~6.15.1, so without it the tree drops toqs@6.15.3. It was restored and left as is. Other overrides (eslint/@eslint/eslintrcajv,tmp,serialize-javascript,diff) are still doing work and untouched.Lockfile note
brace-expansion@1is now installed as nested copies (withbalanced-match@1.0.2) instead of one hoisted copy, becausenpm installre-evaluated placement once theminimatch@10.2.5subtree moved to 5.0.12. Versions all satisfy their ranges;npm ciis clean.Self code review (step 7.5)
2 rounds. Round 1 findings: (Medium) unrelated
@oclif/core/oclif/cli-commandbumps fromnpm audit fixand the integration-test regression they cause -> fixed by dropping them; (Medium)qsoverride retired but still required -> restored. Round 2 found no High/Medium issues. Low: lockfile placement churn noted above. No application code changed, no comments added, no workflow or Dockerfile changes (no Node/Go version moved, so.github/workflowsneeded no sync).Needs human review (not resolved by this PR)
deepmerge@4.3.1via@rollup/plugin-node-resolve@16.0.3. No fixed version exists upstream.csv-parse@4.16.3via@contentstack/cli-utilities > tty-table > csv@5.5.3. Fixed in 7.0.2, but forcing an override across three majors againstcsv@5's expected API cannot be validated by this repo's tests and could change behavior; needs a human decision (or an upstreamtty-table/cli-utilitiesrelease).braceschain above (devDependency majors:lint-staged16,jest30,oclif,shx).Warnings / environment
npm audit fixandnpm viewreturn 403 for@contentstack/cli-commandthrough the repo-local GitHub Packages.npmrcmapping, although the lockfile resolves all@contentstack/*from registry.npmjs.org. Worked around per command with--@contentstack:registry=https://registry.npmjs.org;.npmrcwas not modified.npm run lintreports 107 pre-existing errors in untouchedsrc/files (unchanged by this PR).Validation
npm ci,npm run build,npm test(139 unit tests + 31 integration tests) pass.snyk test --all-projects(1 project, 463 dependencies) is clean for every fixed finding; only the two needs-human-review ids above remain.#claude_code#
🤖 Generated with Claude Code