OSV weekly scan reported 50 known vulnerabilities in pinned deps. This bumps everything with a released, semver-compatible fix: Python (uv.lock): - aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v, GHSA-mq44-7p77-q5h7) - h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer exception documented in pyproject, remove after 2026-08-17) npm (root workspace): - brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29, js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0, mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the streamdown transitive copy is pinned too) - electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major for GHSA-9f4c-93c8-jc8g is deferred to its own PR) npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5, postcss 8.5.23, undici 7.29.0 npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici npm (whatsapp-bridge): body-parser 1.20.6 min-release-age excludes added to .npmrc/website/.npmrc for the sub-2wk CVE-fix releases, each with a removal date. Remaining findings are blocked upstream: cryptography <49 cap (alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x transitive majors, electron 41. Local rescan: 50 -> 19 known vulns, 0 introduced.
25 lines
1.0 KiB
Plaintext
25 lines
1.0 KiB
Plaintext
# needed to prevent bad npm that has min-release-age but not exclude
|
|
engine-strict=true
|
|
|
|
min-release-age=14
|
|
|
|
# fast-uri 3.1.5 includes fixes for vulns (GHSA-7p8r-x3mc-p8w7). remove this when 3.1.5 is > 2wks old (rel 2026-07-31)
|
|
min-release-age-exclude[]=fast-uri
|
|
|
|
# js-yaml 4.3.1 includes fixes for GHSA-5p4m-2wfm-xmqj. remove when > 2wks old (rel 2026-07-31)
|
|
min-release-age-exclude[]=js-yaml
|
|
|
|
# nanoid 3.3.17 includes fixes for GHSA-2v37-7h3g-55p8. remove when > 2wks old (rel 2026-08-03)
|
|
min-release-age-exclude[]=nanoid
|
|
|
|
# mermaid 11.16.1 includes fixes for 5 GHSAs. remove when > 2wks old (rel 2026-08-04)
|
|
min-release-age-exclude[]=mermaid
|
|
|
|
# dompurify 3.4.13 includes fixes for GHSA-55q2-fjhq-7xh7. remove when > 2wks old (rel 2026-08-03)
|
|
min-release-age-exclude[]=dompurify
|
|
|
|
# minimatch 10.2.6 includes fixes for vulns. remove this when 10.2.6 is > 2wks old
|
|
min-release-age-exclude[]=minimatch
|
|
|
|
# brace-expansion 5.0.8 includes fixes for vulns. remove this when 5.0.8 is > 2wks old
|
|
min-release-age-exclude[]=brace-expansion |