The frontend lockfile on main at eac9a62 contains js-yaml 3.15.1 and 4.3.1 plus svgo 4.0.2. Running npm audit --audit-level=high reports two high-severity vulnerable packages and exits 1, blocking Security Scanning and CI Success. PR2071 run34415153948 reproduces this with a lockfile identical to main.
Current advisories:
Update frontend/package-lock.json within the existing parent ranges, including SVGO's required selector dependencies. Preserve package.json and the full-tree audit gate. Verify audit red before and green after, production frontend build, and Jest.
Related LeanerCloud/cloud-commitments-platform#79 covers earlier fast-uri/SVGO advisories; LeanerCloud/cloud-commitments-platform#165 covers the broader gating policy. Neither tracks these current advisory versions. All affected entries are dev dependencies; this report establishes CI failure and vulnerable installed versions, not production exploitability.
The frontend lockfile on main at eac9a62 contains js-yaml 3.15.1 and 4.3.1 plus svgo 4.0.2. Running npm audit --audit-level=high reports two high-severity vulnerable packages and exits 1, blocking Security Scanning and CI Success. PR2071 run34415153948 reproduces this with a lockfile identical to main.
Current advisories:
Update frontend/package-lock.json within the existing parent ranges, including SVGO's required selector dependencies. Preserve package.json and the full-tree audit gate. Verify audit red before and green after, production frontend build, and Jest.
Related LeanerCloud/cloud-commitments-platform#79 covers earlier fast-uri/SVGO advisories; LeanerCloud/cloud-commitments-platform#165 covers the broader gating policy. Neither tracks these current advisory versions. All affected entries are dev dependencies; this report establishes CI failure and vulnerable installed versions, not production exploitability.