Files
hermes-agent/website/.npmrc
ethernet 8789cf9f0c fix(sec): patch the npm advisories main left open
Main (7537de9e7) moved most of the vulnerable locked versions, but some
fixes live only in the lockfiles and some advisories stayed open. This
commit closes the rest:

website/package.json gets durable overrides for js-yaml 4.3.1,
dompurify 3.4.13, mermaid 11.16.1, and tar 7.5.22. The root workspace
gets the same tar override, which moves the tar 6.2.1 copies under
get-windows and @mapbox/node-pre-gyp past twelve open advisories.
Without an override, a reinstall can pull an old transitive copy back
in.

image-size <=2.0.2 has two infinite-loop DoS advisories and no fixed
release upstream. An override points it at @nous-research/image-size
2.0.3, our maintained fork of the real repo. The OSV scanner resolves
the aliased fork cleanly, so no ignore entries are needed.

The photon sidecar moves @opentelemetry/core to 2.10.0. The
whatsapp-bridge gets a body-parser 1.20.6 override, so the lockfile-only
fix from main cannot regress on reinstall.

website/.npmrc gets matching min-release-age exclusions for the fix
releases that are less than two weeks old.

electron stays at 40.10.2. The 41.x fix for GHSA-9f4c-93c8-jc8g brings
back the install failure that bb8280b75 reverted: install.js in 40.10.3+
extracts with an MSVC native binding, which fails on Windows machines
without the VC++ Redistributable. Upstream tracks this in
electron/electron#52481, with no fix released.
2026-08-10 13:49:37 -04:00

35 lines
1.4 KiB
Plaintext

# needed to prevent bad npm that has min-release-age but not exclude
engine-strict=true
min-release-age=14
# fast-uri 3.1.5 includes fixes for vulns (GHSA-7p8r-x3mc-p8w7). remove this when 3.1.5 is > 2wks old (rel 2026-07-31)
min-release-age-exclude[]=fast-uri
# js-yaml 4.3.1 includes fixes for GHSA-5p4m-2wfm-xmqj. remove when > 2wks old (rel 2026-07-31)
min-release-age-exclude[]=js-yaml
# nanoid 3.3.17 includes fixes for GHSA-2v37-7h3g-55p8. remove when > 2wks old (rel 2026-08-03)
min-release-age-exclude[]=nanoid
# mermaid 11.16.1 includes fixes for 5 GHSAs. remove when > 2wks old (rel 2026-08-04)
min-release-age-exclude[]=mermaid
# dompurify 3.4.13 includes fixes for GHSA-55q2-fjhq-7xh7. remove when > 2wks old (rel 2026-08-03)
min-release-age-exclude[]=dompurify
# minimatch 10.2.6 includes fixes for vulns. remove this when 10.2.6 is > 2wks old
min-release-age-exclude[]=minimatch
# brace-expansion 5.0.8 includes fixes for vulns. remove this when 5.0.8 is > 2wks old
min-release-age-exclude[]=brace-expansion
# postcss 8.5.23 includes fixes for vulns. remove this when 8.5.23 is > 2wks old
min-release-age-exclude[]=postcss
# undici 6.28.0 includes fixes for vulns. remove this when 6.28.0 is > 2wks old
min-release-age-exclude[]=undici
# @nous-research/image-size 2.0.3 includes fixes for vulns. remove this when 2.0.3 is > 2wks old
min-release-age-exclude[]=@nous-research/image-size