Skip to content

fix(frontend): 30 high-severity npm-audit vulns reddening Security Scanning repo-wide (postcss/serve/minimatch) #1510

Description

@cristim

Security Scanning red repo-wide: 30 high-severity frontend npm-audit vulns

npm audit in the frontend now exits 1 with 30 high-severity advisories, failing the Security Scanning job (and therefore the CI Success gate) on every open PR, including trivial ones that don't touch the frontend.

Not a code regression: Security Scanning was green on main as of 2026-07-23 (d9eb097) with the same package-lock.json. The npm advisory database has since published new advisories, so npm audit now flags dependencies that were clean 3 days ago.

Advisories (high)

  • postcss <=8.5.17 — Path Traversal in source-map auto-loading (GHSA-r28c-9q8g-f849). fix available via npm audit fix.
  • serve / serve-handler / minimatch — chain of high-severity deps.
  • (30 high total; run npm audit in the frontend for the full list.)

Fix (per owner no-masking-CI-debt directive: fix for real, do not suppress)

  1. In the frontend dir: npm audit fix (semver-compatible) first; re-run npm audit + npm run build + the frontend test/lint to confirm nothing breaks.
  2. For anything remaining that needs npm audit fix --force (major bumps of postcss/serve/etc.): assess each breaking change, bump deliberately, and verify the build + a smoke test of the affected UI.
  3. Do NOT gate-suppress (no --audit-level bump, no || true, no removing the audit step).

Impact

Blocks merge of all current PRs (#1495, #1504, and any future) until resolved, since CI Success aggregates Security Scanning.

Related

Surfaced while merge-checking the MCP PRs (#1495, #1504), neither of which touches the frontend.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions