Skip to content

npm audit gate is red on every PR and blocks release; the obvious override fix breaks Prism #45

Description

@rob-archastro

Problem and author intent

npm audit --audit-level=moderate runs as an early step in both ci.yml and release.yml. It now fails on advisories published since the last green run, so every PR is red before any Python test executes, and the release workflow cannot reach its bump-and-publish steps. This blocks shipping #44 and, downstream, ArchAstro/firstlanding#13724.

The intent is to get the audit gate green again without breaking the Prism mock server the REST contract tests depend on.

Observed evidence

Last green run on main was 2026-08-19 (72687224c, CI + Release both success). PR #44, whose diff touches only src/archastro/platform/runtime/http_client.py and tests/test_http_client.py, fails all three matrix legs at the Audit JS tooling dependencies step:

9 vulnerabilities (1 moderate, 8 high)
##[error]Process completed with exit code 1.

The Python tests never run. The failure is calendar drift, not a code change.

Note package.json already carries an overrides block pinning fast-uri to 4.1.2 — and the new advisory range is fast-uri 4.0.0 - 4.1.2, so a previously-remediating pin is now itself the vulnerable version.

What I verified, including the part that does not work

Bumping two overrides clears three of the nine:

"fast-uri": "4.1.4",
"qs": "6.16.0"

→ 6 high severity vulnerabilities.

The remaining six are one chain, all @faker-js/faker <=10.4.0 (GHSA-qxc2-j82w-r537, arbitrary code execution via helpers.fake):

node_modules/postman-collection/node_modules/@faker-js/faker
  node_modules/postman-collection
    node_modules/@stoplight/http-spec
      node_modules/@stoplight/prism-http
        node_modules/@stoplight/prism-cli

Adding "@faker-js/faker": "10.5.0" to overrides does reach found 0 vulnerabilities — and breaks Prism. uv run pytest tests/contract then dies during collection:

INTERNALERROR> at Object.<anonymous> (node_modules/postman-collection/lib/superstring/index.js:2:24)

postman-collection depends on the pre-10.5 faker API, so forcing the override forward trades a red audit for 2616 uncollectable contract tests. There is no newer Prism to escape to: @stoplight/prism-cli is pinned at 5.16.0 and npm view @stoplight/prism-cli version is also 5.16.0.

So the easy fix is not available, which is why this is its own issue rather than a line in #44.

Requested change

Pick one and say which in the PR:

  1. Bump fast-uri and qs (clean, no downside), then narrow the audit gate for the faker chain specifically — an npm audit --audit-level=moderate plus an explicit, dated, justified exclusion for GHSA-qxc2-j82w-r537, with a comment naming why it is acceptable: Prism is a dev-only mock server, never shipped in the wheel, and helpers.fake is not reachable from how we drive it. Blanket-raising --audit-level to high or deleting the step is not acceptable; it would hide the next real advisory too.
  2. Replace the Prism mock server for REST contract tests with something whose dependency tree we can keep clean.

Option 1 is the smaller change and keeps the gate meaningful. Option 2 is the durable one if this chain keeps re-breaking.

Either way, verify with npm audit --audit-level=moderate and uv run pytest tests/contract (2616 tests), since the whole trap here is that the two move in opposite directions.

Scope

CI and dev tooling only. No SDK source change, nothing in the published wheel. Risk: low, but it gates every other PR in this repo until it lands.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions