Skip to content

fix(ci): lockfile pins fast-uri 3.1.5 with four high advisories, npm audit gate is red #1973

Description

@cristim

Summary

frontend/package-lock.json pins the dev-only transitive dependency fast-uri at 3.1.5, which four GitHub advisories (GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp) cover; the first patched release is 3.1.6. The Security Scanning job runs npm audit --audit-level=high in frontend/, so it exits 1 on this commit and reddens CI Success, which is a required check on main. The package is reached only through devDependencies (babel-loader -> schema-utils -> ajv, serve -> ajv) and does not enter the shipped webpack bundle, so the live impact is the blocked merge queue, not runtime SSRF. LeanerCloud/cloud-commitments-platform#79 tracked an earlier fast-uri advisory that a 2026-07-27 sweep found already resolved at 3.1.4; this is a new advisory range against the newer pin, and LeanerCloud/cloud-commitments-platform#165 is the standing policy question about dev-only advisories gating merges.

Location

  • frontend/package-lock.json:5754 at 3c0f8ac
  • .github/workflows/ci.yml:663 (the npm audit --audit-level=high step)

Failure scenario

Any push to any PR runs Security Scanning. npm ci --ignore-scripts && npm audit --audit-level=high in frontend/ exits 1 with 1 high severity vulnerability against fast-uri@3.1.5. CI Success fails, so no PR can merge until the lockfile moves, regardless of whether it touches JavaScript. Measured locally on the pinned commit.

Evidence

"node_modules/fast-uri": {
  "version": "3.1.5",
  "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz",

npm ls fast-uri --omit=dev returns empty; frontend/package.json lists only @types/qrcode, chart.js and qrcode under dependencies.

Suggested fix

Refresh the lockfile so fast-uri resolves to 3.1.6 or later; it is a patch bump inside the existing semver ranges, so package.json does not change. Do not suppress with --omit=dev or an audit-level change.


Found by the 2026-09-02 codebase audit, finding A15-001, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions