Skip to content

chore(deps): clear dev-dependency audit findings - #770

Merged
vscheuber merged 1 commit into
mainfrom
fix/dev-audit-braces-sprintf
Oct 9, 2026
Merged

vscheuber merged 1 commit into
mainfrom
fix/dev-audit-braces-sprintf

Conversation

@vscheuber

Copy link
Copy Markdown
Contributor

Summary

npm audit in frodo-cli currently reports 25 vulnerable package nodes (20 moderate, 5 high). That number is 2 distinct advisories, all dev-only, counted once per package node that pulls them in:

  • braces ≤ 3.0.3 via del → globby → micromatch — no patched braces release exists. del is an unused devDependency: no source, test, tool, script or workflow references it. Dropping it removes the whole chain.
  • sprintf-js ≤ 1.1.3 via js-yaml@3 → argparse@1 → sprintf-js — no patched sprintf-js release exists; the fix is avoiding argparse@1 (used only by js-yaml's CLI binary, never by library code we import).

Change

  • package.json: remove the unused del devDependency; add "overrides": { "argparse": "^2.0.1" }
  • package-lock.json: regenerated — the entire del/globby/micromatch/braces and argparse/sprintf-js trees are gone

Result

  • npm audit: 0 vulnerabilities
  • Dependabot: the 1 open medium alert (sprintf-js) resolves with the regenerated lockfile; the auto-dismissed braces alert becomes moot

Not a shipping risk either way

frodo-cli declares zero runtime dependencies; the flagged packages are all in the dev tree and none of their code appears in the built bundle.

Verification

  • npm@10 ci --dry-run and npm@11 ci --dry-run accept the lockfile
  • npm run check clean
  • Full suite: 632 suites / 1824 tests / 8484 snapshots pass with the change

🤖 Generated with Claude Code

npm audit reports 25 vulnerable package nodes (20 moderate, 5 high)
across 2 distinct advisories, all dev-only: braces <= 3.0.3 (via the
unused `del` devDependency -> globby -> micromatch; no patched braces
exists) and sprintf-js <= 1.1.3 (via js-yaml 3 -> argparse 1 ->
sprintf-js; no patched sprintf-js exists).

Drop the unused `del` devDependency (no source, test, tool or workflow
references it) and add an argparse ^2.0.1 override (argparse 2 has no
sprintf-js dependency). npm audit now reports 0 vulnerabilities;
Dependabot's 1 open medium alert (sprintf-js) resolves with the lockfile
regeneration, and its auto-dismissed braces alert becomes moot.

None of the affected packages ship: the package has zero runtime
dependencies and none of their code is in the bundle.

Lockfile verified with npm@10 and npm@11 `ci --dry-run`; full suite
(632 suites / 1824 tests / 8484 snapshots) green with the change.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@vscheuber
vscheuber merged commit fd661af into main Oct 9, 2026
13 checks passed
@vscheuber
vscheuber deleted the fix/dev-audit-braces-sprintf branch October 9, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant