Problem and author intent
npm audit --audit-level=moderate runs as an early step in both ci.yml and release.yml. It now fails on advisories published since the last green run, so every PR is red before any Python test executes, and the release workflow cannot reach its bump-and-publish steps. This blocks shipping #44 and, downstream, ArchAstro/firstlanding#13724.
The intent is to get the audit gate green again without breaking the Prism mock server the REST contract tests depend on.
Observed evidence
Last green run on main was 2026-08-19 (72687224c, CI + Release both success). PR #44, whose diff touches only src/archastro/platform/runtime/http_client.py and tests/test_http_client.py, fails all three matrix legs at the Audit JS tooling dependencies step:
9 vulnerabilities (1 moderate, 8 high)
##[error]Process completed with exit code 1.
The Python tests never run. The failure is calendar drift, not a code change.
Note package.json already carries an overrides block pinning fast-uri to 4.1.2 — and the new advisory range is fast-uri 4.0.0 - 4.1.2, so a previously-remediating pin is now itself the vulnerable version.
What I verified, including the part that does not work
Bumping two overrides clears three of the nine:
"fast-uri": "4.1.4",
"qs": "6.16.0"
→ 6 high severity vulnerabilities.
The remaining six are one chain, all @faker-js/faker <=10.4.0 (GHSA-qxc2-j82w-r537, arbitrary code execution via helpers.fake):
node_modules/postman-collection/node_modules/@faker-js/faker
node_modules/postman-collection
node_modules/@stoplight/http-spec
node_modules/@stoplight/prism-http
node_modules/@stoplight/prism-cli
Adding "@faker-js/faker": "10.5.0" to overrides does reach found 0 vulnerabilities — and breaks Prism. uv run pytest tests/contract then dies during collection:
INTERNALERROR> at Object.<anonymous> (node_modules/postman-collection/lib/superstring/index.js:2:24)
postman-collection depends on the pre-10.5 faker API, so forcing the override forward trades a red audit for 2616 uncollectable contract tests. There is no newer Prism to escape to: @stoplight/prism-cli is pinned at 5.16.0 and npm view @stoplight/prism-cli version is also 5.16.0.
So the easy fix is not available, which is why this is its own issue rather than a line in #44.
Requested change
Pick one and say which in the PR:
- Bump
fast-uri and qs (clean, no downside), then narrow the audit gate for the faker chain specifically — an npm audit --audit-level=moderate plus an explicit, dated, justified exclusion for GHSA-qxc2-j82w-r537, with a comment naming why it is acceptable: Prism is a dev-only mock server, never shipped in the wheel, and helpers.fake is not reachable from how we drive it. Blanket-raising --audit-level to high or deleting the step is not acceptable; it would hide the next real advisory too.
- Replace the Prism mock server for REST contract tests with something whose dependency tree we can keep clean.
Option 1 is the smaller change and keeps the gate meaningful. Option 2 is the durable one if this chain keeps re-breaking.
Either way, verify with npm audit --audit-level=moderate and uv run pytest tests/contract (2616 tests), since the whole trap here is that the two move in opposite directions.
Scope
CI and dev tooling only. No SDK source change, nothing in the published wheel. Risk: low, but it gates every other PR in this repo until it lands.
Problem and author intent
npm audit --audit-level=moderateruns as an early step in bothci.ymlandrelease.yml. It now fails on advisories published since the last green run, so every PR is red before any Python test executes, and the release workflow cannot reach its bump-and-publish steps. This blocks shipping #44 and, downstream, ArchAstro/firstlanding#13724.The intent is to get the audit gate green again without breaking the Prism mock server the REST contract tests depend on.
Observed evidence
Last green run on
mainwas 2026-08-19 (72687224c, CI + Release both success). PR #44, whose diff touches onlysrc/archastro/platform/runtime/http_client.pyandtests/test_http_client.py, fails all three matrix legs at theAudit JS tooling dependenciesstep:The Python tests never run. The failure is calendar drift, not a code change.
Note
package.jsonalready carries anoverridesblock pinningfast-urito4.1.2— and the new advisory range isfast-uri 4.0.0 - 4.1.2, so a previously-remediating pin is now itself the vulnerable version.What I verified, including the part that does not work
Bumping two overrides clears three of the nine:
→
6 high severity vulnerabilities.The remaining six are one chain, all
@faker-js/faker <=10.4.0(GHSA-qxc2-j82w-r537, arbitrary code execution viahelpers.fake):Adding
"@faker-js/faker": "10.5.0"tooverridesdoes reachfound 0 vulnerabilities— and breaks Prism.uv run pytest tests/contractthen dies during collection:postman-collectiondepends on the pre-10.5 faker API, so forcing the override forward trades a red audit for 2616 uncollectable contract tests. There is no newer Prism to escape to:@stoplight/prism-cliis pinned at5.16.0andnpm view @stoplight/prism-cli versionis also5.16.0.So the easy fix is not available, which is why this is its own issue rather than a line in #44.
Requested change
Pick one and say which in the PR:
fast-uriandqs(clean, no downside), then narrow the audit gate for the faker chain specifically — annpm audit --audit-level=moderateplus an explicit, dated, justified exclusion for GHSA-qxc2-j82w-r537, with a comment naming why it is acceptable: Prism is a dev-only mock server, never shipped in the wheel, andhelpers.fakeis not reachable from how we drive it. Blanket-raising--audit-leveltohighor deleting the step is not acceptable; it would hide the next real advisory too.Option 1 is the smaller change and keeps the gate meaningful. Option 2 is the durable one if this chain keeps re-breaking.
Either way, verify with
npm audit --audit-level=moderateanduv run pytest tests/contract(2616 tests), since the whole trap here is that the two move in opposite directions.Scope
CI and dev tooling only. No SDK source change, nothing in the published wheel. Risk: low, but it gates every other PR in this repo until it lands.