Security Scanning red repo-wide: 30 high-severity frontend npm-audit vulns
npm audit in the frontend now exits 1 with 30 high-severity advisories, failing the Security Scanning job (and therefore the CI Success gate) on every open PR, including trivial ones that don't touch the frontend.
Not a code regression: Security Scanning was green on main as of 2026-07-23 (d9eb097) with the same package-lock.json. The npm advisory database has since published new advisories, so npm audit now flags dependencies that were clean 3 days ago.
Advisories (high)
- postcss <=8.5.17 — Path Traversal in source-map auto-loading (GHSA-r28c-9q8g-f849).
fix available via npm audit fix.
- serve / serve-handler / minimatch — chain of high-severity deps.
- (30 high total; run
npm audit in the frontend for the full list.)
Fix (per owner no-masking-CI-debt directive: fix for real, do not suppress)
- In the frontend dir:
npm audit fix (semver-compatible) first; re-run npm audit + npm run build + the frontend test/lint to confirm nothing breaks.
- For anything remaining that needs
npm audit fix --force (major bumps of postcss/serve/etc.): assess each breaking change, bump deliberately, and verify the build + a smoke test of the affected UI.
- Do NOT gate-suppress (no
--audit-level bump, no || true, no removing the audit step).
Impact
Blocks merge of all current PRs (#1495, #1504, and any future) until resolved, since CI Success aggregates Security Scanning.
Related
Surfaced while merge-checking the MCP PRs (#1495, #1504), neither of which touches the frontend.
Security Scanning red repo-wide: 30 high-severity frontend npm-audit vulns
npm auditin the frontend now exits 1 with 30 high-severity advisories, failing theSecurity Scanningjob (and therefore theCI Successgate) on every open PR, including trivial ones that don't touch the frontend.Not a code regression: Security Scanning was green on
mainas of 2026-07-23 (d9eb097) with the samepackage-lock.json. The npm advisory database has since published new advisories, sonpm auditnow flags dependencies that were clean 3 days ago.Advisories (high)
fix available via npm audit fix.npm auditin the frontend for the full list.)Fix (per owner no-masking-CI-debt directive: fix for real, do not suppress)
npm audit fix(semver-compatible) first; re-runnpm audit+npm run build+ the frontend test/lint to confirm nothing breaks.npm audit fix --force(major bumps of postcss/serve/etc.): assess each breaking change, bump deliberately, and verify the build + a smoke test of the affected UI.--audit-levelbump, no|| true, no removing the audit step).Impact
Blocks merge of all current PRs (#1495, #1504, and any future) until resolved, since
CI SuccessaggregatesSecurity Scanning.Related
Surfaced while merge-checking the MCP PRs (#1495, #1504), neither of which touches the frontend.