fix(security): @nuxtjs/mdc ^0.22.2 and the lockfile's HIGH/CRITICAL advisories; retire scan.yml #70
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!70
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/lockfile-advisories-20261008"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
baseline-security (required) and scan / trivy-fs are red on main. The runs are #1170 and #1172 (global runs 9663 and 9665). A scan with today's trivy database reports 25 HIGH/CRITICAL findings in
package-lock.json. After this PR, a gate-equivalent scan reports 0.What changes
@nuxtjs/mdc^0.21.1→^0.22.2(lock 0.21.1 → 0.22.2)packages/*peer on^3.0.0, which resolves to the workspace root. The$@nuxtjs/mdcoverride #59 needed is therefore gone.overrides.brace-expansion5.0.9→5.0.12npm update …with npm 11.19.0, the Node 24 npm thatdeploy-pages.ymluses. The lockfile keeps its npm 11 shape. svgo 4.1.0 brings css-select 6 and css-what 7, as on nis/atlas. 54 version moves in all, nothing removed..security-ignore(new)@nuxt/devtools3.x cannot load: an override breaksnuxt prepare(proven in nis/template-service#5). All are dev-server or build-time only. Each comment carries the on-expiry command.scripts/sync-engine.mjs,kit/python/components/)kit/python/components/*.py, becauseemitPythonwrote JStrue/false/null/undefinedand unquoted enum defaults, and props namedforandasmade four files unparseable. The emitter now writes Python literals (pythonDefault()), adds PEP 8's trailing underscore to keyword names (pythonName()), and importsOptionalonly where it's used. I regenerated the Python target only (177 modules). That includes the four files that had drifted behind their Vue props and the missingtux_hero_canvas_sol.py. pyflakes is clean, and every module imports and instantiates. Maintainer's call, 2026-10-08: fix the emitter and regenerate Python only. The PHP/.NET/Swift/Kotlin emitters share the raw-literal pattern and are a follow-up..forgejo/workflows/scan.ymldeletedtrivy fsas the required baseline-security gate but never read.security-ignore, so an advisory with no fix kept it red forever. It also took a runner slot on every push. Its fresh-forge seed is retired in nis/forgejo-stack in the same change (nis/forgejo-stack#239).CHANGELOG.md## [Unreleased]→ Security entry.Checks (local, Node 24.21.0, 2026-10-08)
npm cipasses..mdfiles parse to identical output (body, data, toc) under@nuxtjs/mdc0.21.1 and 0.22.2.nuxt typecheckreports the same 189 errors as main, by file, line and code, with none new. Those 189 are pre-existing on main; nothing on the forge runs typecheck here. tti/tti-ai-studio's CI hit them when it type-checked against main.vitest runpasses 218 files / 677 tests.npm packtarball (2,061 files) contains no node-forge, simple-git or braces code.NUXT_PAGES=1 npm run generatesucceeds. The output contains none of that code either; the only hits are this changelog entry rendered on/changelog.Not covered:
npm run lintfails on main and here with Cannot find module 'eslint', because eslint isn't in devDependencies. Separately, publish-package is red on the v3.0.0 tag push (the known missingPACKAGE_TOKEN). Neither is changed here.After this merges: close #59 and #62, update #43 from main and merge it, and rebase or merge #69 as you prefer. #69 changes only
package.json's version among these files.AI review · advisory
The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}
AI review · advisory
The AI panel couldn't review this change right now (it will review the next push). Details for admins: panel HTTP 401: {"error": {"message": "missing Forgejo credential", "type": "auth", "code": 401}}
Merging on the maintainer's go (2026-10-08), as the admin merge; the branch rule wants one approval.
CI is green on
d21ec1f. The baseline-security log shows:Active suppressions: 6 trivy;SCA: no HIGH/CRITICAL findingsandno leaks found;OK: no undefined names;The AI review panel is paused (TAMUS key, since 2026-10-07), and tti-ux has no non-AI review lane yet. In their place:
scan.ymlremoval;3fff848;npm ci; typecheck shows the same 189 errors as main, none new; vitest 677/677; the 123.mdfiles parse identically under mdc 0.21.1 and 0.22.2;npm packand the Pages build are clean; the regenerated Python kit is pyflakes-clean and every module imports and instantiates.This supersedes #59 (mdc) and #62 (brace-expansion). #43 (seed) can be updated from main next; its
.security-ignoreheader and braces line match this one. The tti-ux main typecheck debt (189) and the other emitters' raw literals are follow-ups.