Skip to content

chore(site): take in-range security updates in the lockfile - #171

Merged
Seungpyo1007 merged 1 commit into
developfrom
chore/site-deps-in-range
Sep 11, 2026
Merged

chore(site): take in-range security updates in the lockfile#171
Seungpyo1007 merged 1 commit into
developfrom
chore/site-deps-in-range

Conversation

@Seungpyo1007

@Seungpyo1007 Seungpyo1007 commented Sep 11, 2026

Copy link
Copy Markdown
Member

Lockfile-only security update for the site. package.json is unchanged — every bump stays inside the ranges already declared.

js-yaml     4.1.1  -> 4.3.2      smol-toml  1.6.1  -> 1.8.0
nanoid      3.3.12 -> 3.3.19     svgo       4.0.1  -> 4.1.0
postcss     8.5.15 -> 8.5.28     vite       6.4.2  -> 6.4.3
css-select  5.2.2  -> 6.0.0      css-what   6.2.2  -> 7.0.0
sax         1.6.0  -> 1.6.1

npm audit goes from 9 vulnerabilities (1 critical, 7 high, 1 low) to 3.

Verified by building — CI does not

TechAPI's PR checks validate data but never build the site; the build only runs on deploy from main. So the site was built locally both ways, from a checkout without the million-file dump (astro build, skipping prebuild, which needs index.json's git history):

lockfile npm ci astro build pages dist files warnings / errors
current ok ok 2 7 0
this PR ok ok 2 7 0

What is left, and why it is not in this PR

The remaining three — astro (critical), sharp (high), esbuild (low) — only clear with astro 5 → 7, a semver-major upgrade that needs its own migration and review.

Actual exposure is low in the meantime:

  • The critical astro advisories are XSS through define:vars and replay of server-island parameters. The site uses neither — no define:vars anywhere in site/src, and it is a static build (no output: server, no adapter).
  • sharp, esbuild, and most of what this PR fixes (vite / esbuild dev servers, launch-editor, postcss source maps) run on the build machine, not in what visitors download.

Refs #1

Closes #19

npm audit fix --package-lock-only; package.json is unchanged, so every
bump stays inside the declared ranges. 9 advisories drop to 3. The site
builds identically before and after (2 pages, 7 files, no warnings).

The remaining three (astro, sharp, esbuild) need astro 5 -> 7, a major
upgrade left for its own change. The critical astro advisories need
define:vars or server islands, and this static site uses neither.

Refs #1
@Seungpyo1007 Seungpyo1007 self-assigned this Sep 11, 2026
@github-actions github-actions Bot added enhancement New feature or request site Homepage and public site changes labels Sep 11, 2026
@Seungpyo1007 Seungpyo1007 moved this from Todo to In Progress in TechAPI-Project Sep 11, 2026
@Seungpyo1007

Copy link
Copy Markdown
Member Author

Output check: the two builds (current lockfile vs this PR) were compared file by file. All 7 files in dist/ — including the content-hashed _astro/*.js and *.css bundles — are byte-identical. The update changes nothing a visitor downloads; it only changes what runs on the build machine.

@Seungpyo1007
Seungpyo1007 merged commit cd53784 into develop Sep 11, 2026
2 checks passed
@Seungpyo1007
Seungpyo1007 deleted the chore/site-deps-in-range branch September 11, 2026 03:03
@github-project-automation github-project-automation Bot moved this from In Progress to Done in TechAPI-Project Sep 11, 2026
@TechEngineBot

Copy link
Copy Markdown
Member

TechEngine change review: PASS

Check Result
python -m app.validate PASS
python integrity_check.py TechAPI/data --strict PASS
cd TechAPI/site && npm ci && npm run build PASS

Changed data

Category Added Modified Deleted Added verified Added unverified Added Kaggle-sourced
brand 0 0 0 0 0 0
soc 0 0 0 0 0 0
smartphone 0 0 0 0 0 0
tablet 0 0 0 0 0 0
watch 0 0 0 0 0 0
pda 0 0 0 0 0 0
gpu 0 0 0 0 0 0
cpu 16 82 0 16 0 0

Changed record examples

cpu added

  • cpu/intel/2008/consumer/core-2-duo-e8290-14.json - Intel Core 2 Duo E8290 [ 14 ]
  • cpu/intel/2010/consumer/core-i7-660lm.json - Intel Core i7-660LM
  • cpu/intel/2011/consumer/core-i7-2629m.json - Intel Core i7-2629M
  • cpu/intel/2011/consumer/core-i7-2649m.json - Intel Core i7-2649M
  • cpu/intel/2011/consumer/core-i7-2657m.json - Intel Core i7-2657M
  • cpu/intel/2013/consumer/core-i7-4950hq.json - Intel Core i7-4950HQ
  • cpu/intel/2015/consumer/core-i5-5350h.json - Intel Core i5-5350H
  • cpu/intel/2015/consumer/core-i7-5750hq.json - Intel Core i7-5750HQ
  • cpu/intel/2016/consumer/core-i5-6585r.json - Intel Core i5-6585R
  • cpu/intel/2016/consumer/core-i5-6685r.json - Intel Core i5-6685R
  • cpu/intel/2016/consumer/core-i7-6785r.json - Intel Core i7-6785R
  • cpu/intel/2016/consumer/core-i7-6870hq.json - Intel Core i7-6870HQ
  • cpu/intel/2016/consumer/core-i7-6970hq.json - Intel Core i7-6970HQ
  • cpu/intel/2018/consumer/core-i3-8100h.json - Intel Core i3-8100H
  • cpu/intel/2018/consumer/core-i5-8400b.json - Intel Core i5-8400B
  • ... 1 more

cpu modified

  • cpu/amd/2009/consumer/amd-sempron-si-40.json - AMD Sempron SI-40
  • cpu/amd/2009/consumer/amd-sempron-si-42.json - AMD Sempron SI-42
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mk-36.json - AMD Turion 64 Mobile MK-36
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mk-38.json - AMD Turion 64 Mobile MK-38
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-28.json - AMD Turion 64 Mobile ML-28
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-30.json - AMD Turion 64 Mobile ML-30
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-34.json - AMD Turion 64 Mobile ML-34
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-37.json - AMD Turion 64 Mobile ML-37
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-40.json - AMD Turion 64 Mobile ML-40
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-42.json - AMD Turion 64 Mobile ML-42
  • cpu/amd/2009/consumer/amd-turion-64-mobile-ml-44.json - AMD Turion 64 Mobile ML-44
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mt-30.json - AMD Turion 64 Mobile MT-30
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mt-32.json - AMD Turion 64 Mobile MT-32
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mt-34.json - AMD Turion 64 Mobile MT-34
  • cpu/amd/2009/consumer/amd-turion-64-mobile-mt-37.json - AMD Turion 64 Mobile MT-37
  • ... 67 more

Heuristic review

  • Added records by manufacturer/brand: intel: 16
  • Added records by source class: other: 16
  • Heuristic warnings: none found.

Changed site

Area Added Modified Deleted
homepage/site 0 1 0

Modified site files

  • site/package-lock.json

@TechEngineBot

Copy link
Copy Markdown
Member

TechEngine validation stats: PASS

Data summary

Category Total Verified Unverified Missing verified Tracked Verified % of tracked
brand 207 24 183 0 207 11.6%
soc 2104 146 1958 0 2104 6.9%
smartphone 93396 17384 76012 0 93396 18.6%
tablet 3455 218 3237 0 3455 6.3%
watch 433 18 415 0 433 4.2%
pda 140 66 74 0 140 47.1%
gpu 2030 809 1221 0 2030 39.9%
cpu 3993 2704 1289 0 3993 67.7%
all 105758 21369 84389 0 105758 20.2%

Warning

Tracked verified coverage is below 50% for watch 4.2% (18/433), tablet 6.3% (218/3455), soc 6.9% (146/2104), brand 11.6% (24/207), smartphone 18.6% (17384/93396), all 20.2% (21369/105758), gpu 39.9% (809/2030), pda 47.1% (66/140).
Tracked coverage excludes records missing the verified field; see the Missing verified column for those records.
This does not fail validation. Keep imported records verified: false until manual audit, but treat this as follow-up verification work before relying on the affected categories as curated data.

Validation notes

  • Full advisory outlier listings are suppressed on successful runs because they are dataset-wide and mostly stable between PRs.
  • Failure runs still include a detailed log excerpt for debugging.

Key output:

## app.validate
## integrity_check.py --strict
loaded CPU=3993 GPU=2030
✅ integrity gate: no hard anomalies.
Integrity section Flagged lines
structural 0
CPU name/tier consistency (desktop mainstream only) 0
CPU single>multi (cinebench/geekbench — should be multi>=single) 0
CPU era-vs-score outliers 8
CPU cross-source ratio outliers (possible wrong-variant) 152
GPU cross-source ratio outliers + sanity 18

Homepage build:

03:57:30 [build] 2 page(s) built in 818.39s
03:57:30 [build] Complete!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request site Homepage and public site changes

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Track homepage and site improvements

2 participants