Files
hermes-agent/hermes_cli
joaomarcos d76c77beed fix(doctor): stop prescribing audit fixes that updates revert (#116774)
The doctor "Browser tools (agent-browser)" row audits the root workspace
tree (npm audit --workspaces=false), whose versions come from the committed
package-lock.json. hermes update reinstalls that exact state via npm ci
(_run_npm_install_deterministic never mutates the lockfile), so the
previously prescribed local `npm audit fix --workspaces=false` was wiped on
the next update and the finding returned - a fix/reintroduce loop (#116774).

- Bump the vulnerable root lockfile pins so the shipped tree audits clean:
  browserslist 4.28.6 -> 4.29.0 (high: GHSA-c83g-rgw3-j3cx,
  GHSA-73wf-gq98-2v4g), baseline-browser-mapping 2.10.43 -> 2.11.25
  (moderate: GHSA-w5vr-8v7q-w6rv), plus updated transitive deps
  (caniuse-lite, electron-to-chromium, node-releases,
  update-browserslist-db); also syncs the stale bootstrap-installer
  lockfile entry to its manifest version. npm audit --workspaces=false now
  reports 0 vulnerabilities.

- Rework the npm-audit remedy for every doctor row: the durable fix is an
  upstream lockfile bump; never prescribe a local mutating fix command
  (workspace-scoped rows already omitted it; the root row prescribed the
  doomed one).

- Invariant tests in tests/hermes_cli/test_doctor_audit_remedy.py: the
  remedy must not prescribe a mutating npm audit fix (proven red on base)
  and must name the lockfile-bump remedy.
2026-09-20 15:57:25 -07:00
..
…
…
…
…
…
…
…