Resolves the four advisories that reach the production dependency tree. The other 16 npm audit reports are devDependencies-only (Remotion, Puppeteer, postcss, the eslint/tsx toolchain) and never ship to users. - @fastify/static 9.1.3 -> 10.1.3 GHSA-8pvw-jcv7-9cmj (authz bypass via non-canonical URL paths). Covers <=10.1.1, so all of 9.x is affected and the fix exists only on the 10.x line. - find-my-way 9.6.0 -> 9.8.0 GHSA-c96f-x56v-gq3h (HTTP/2 DDoS) - fast-uri 3.1.2 -> 3.1.5 GHSA-v2hh-gcrm-f6hx (host confusion) - brace-expansion -> 5.0.9/1.1.18 GHSA-3jxr-9vmj-r5cp (expansion DoS) The last three are transitive and needed only a lockfile re-resolve, so no overrides were introduced. The @fastify/static major changes setHeaders' first argument from a Node ServerResponse to a FastifyReply. Two consequences: 1. res.setHeader() -> reply.header(). The v9 body throws TypeError from inside the plugin on every static request. 2. Precedence flips, silently. The callback used to write to the raw response and lose to the route's staged reply headers; it now writes to the reply and wins. That gave /sw.js a year of immutable in place of the no-cache, no-store its route sets, pinning a service worker on every client with no server-side recovery. A route that already set Cache-Control now keeps it. Verified against v9 to confirm the sw.js behaviour is a regression and not a pre-existing bug. ws appears in npm audit but production is on 8.21.0, outside the vulnerable range; the only affected copy is bundled under @remotion/renderer (dev-only, and remotion is pinned at 4.0.473 because the compositor refuses to start on a version mismatch). Adds test/static-cache-headers.test.ts, which drives a real server and covers a caching contract that had no test at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2.1 KiB
aicodeman
| aicodeman |
|---|
| patch |
Clear every production-reachable npm advisory, and fix a service-worker caching regression the upgrade exposed.
npm audit reported 20 advisories, but 16 were devDependencies-only (Remotion, Puppeteer, postcss, the eslint/tsx toolchain) and never reached anyone installing the package. Four reached production and are now resolved:
@fastify/static9.1.3 to 10.1.3 — GHSA-8pvw-jcv7-9cmj, authorization bypass via non-canonical URL paths. The advisory covers<=10.1.1, so the entire 9.x line is affected and the fix only exists on 10.x.find-my-way9.6.0 to 9.8.0 — GHSA-c96f-x56v-gq3h (HTTP/2 DDoS). Not exploitable here since Codeman does not enable HTTP/2, fixed anyway.fast-uri3.1.2 to 3.1.5 — GHSA-v2hh-gcrm-f6hx, host confusion via a literal backslash authority delimiter.brace-expansionto 5.0.9 / 1.1.18 — GHSA-3jxr-9vmj-r5cp, exponential-time expansion DoS.
The last three were transitive and only needed a lockfile re-resolve; no overrides were added.
The @fastify/static major changes the setHeaders callback's first argument from a Node ServerResponse to a FastifyReply, which required two fixes:
res.setHeader()becamereply.header(). A v9-style body throwsTypeError: res.setHeader is not a functionfrom inside the plugin on every static request.- That change also flips precedence, silently. The callback used to write to the raw response and be overwritten by the route's staged reply headers; it now writes to the reply and wins instead. That handed
/sw.jsa year ofimmutablein place of theno-cache, no-storeits route sets, which would pin a service worker on every client with no server-side way to recover. A route that already setCache-Controlnow keeps it.
ws also appears in npm audit but production is already on 8.21.0, outside the vulnerable range; the only affected copy is bundled under @remotion/renderer and is dev-only.
Adds test/static-cache-headers.test.ts, which drives a real server and covers the caching contract that had no test at all, and moves the floors in test/dependency-security.test.ts up to the patched versions.