Summary
frontend/package-lock.json pins the dev-only transitive dependency fast-uri at 3.1.5, which four GitHub advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp) cover; the first patched release is 3.1.6. The Security Scanning job runs npm audit --audit-level=high in frontend/, so it exits 1 on this commit and reddens CI Success, which is a required check on main. The package is reached only through devDependencies (babel-loader -> schema-utils -> ajv, serve -> ajv) and does not enter the shipped webpack bundle, so the live impact is the blocked merge queue, not runtime SSRF. LeanerCloud/cloud-commitments-platform#79 tracked an earlier fast-uri advisory that a 2026-07-27 sweep found already resolved at 3.1.4; this is a new advisory range against the newer pin, and LeanerCloud/cloud-commitments-platform#165 is the standing policy question about dev-only advisories gating merges.
Location
frontend/package-lock.json:5754 at 3c0f8ac
.github/workflows/ci.yml:663 (the npm audit --audit-level=high step)
Failure scenario
Any push to any PR runs Security Scanning. npm ci --ignore-scripts && npm audit --audit-level=high in frontend/ exits 1 with 1 high severity vulnerability against fast-uri@3.1.5. CI Success fails, so no PR can merge until the lockfile moves, regardless of whether it touches JavaScript. Measured locally on the pinned commit.
Evidence
"node_modules/fast-uri": {
"version": "3.1.5",
"resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz",
npm ls fast-uri --omit=dev returns empty; frontend/package.json lists only @types/qrcode, chart.js and qrcode under dependencies.
Suggested fix
Refresh the lockfile so fast-uri resolves to 3.1.6 or later; it is a patch bump inside the existing semver ranges, so package.json does not change. Do not suppress with --omit=dev or an audit-level change.
Found by the 2026-09-02 codebase audit, finding A15-001, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
frontend/package-lock.jsonpins the dev-only transitive dependencyfast-uriat 3.1.5, which four GitHub advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp) cover; the first patched release is 3.1.6. The Security Scanning job runsnpm audit --audit-level=highinfrontend/, so it exits 1 on this commit and reddensCI Success, which is a required check onmain. The package is reached only through devDependencies (babel-loader -> schema-utils -> ajv,serve -> ajv) and does not enter the shipped webpack bundle, so the live impact is the blocked merge queue, not runtime SSRF. LeanerCloud/cloud-commitments-platform#79 tracked an earlierfast-uriadvisory that a 2026-07-27 sweep found already resolved at 3.1.4; this is a new advisory range against the newer pin, and LeanerCloud/cloud-commitments-platform#165 is the standing policy question about dev-only advisories gating merges.Location
frontend/package-lock.json:5754at 3c0f8ac.github/workflows/ci.yml:663(thenpm audit --audit-level=highstep)Failure scenario
Any push to any PR runs Security Scanning.
npm ci --ignore-scripts && npm audit --audit-level=highinfrontend/exits 1 with1 high severity vulnerabilityagainstfast-uri@3.1.5.CI Successfails, so no PR can merge until the lockfile moves, regardless of whether it touches JavaScript. Measured locally on the pinned commit.Evidence
npm ls fast-uri --omit=devreturns empty;frontend/package.jsonlists only@types/qrcode,chart.jsandqrcodeunderdependencies.Suggested fix
Refresh the lockfile so
fast-uriresolves to 3.1.6 or later; it is a patch bump inside the existing semver ranges, sopackage.jsondoes not change. Do not suppress with--omit=devor an audit-level change.Found by the 2026-09-02 codebase audit, finding
A15-001, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.