You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
nanoid <3.3.18 — custom generators can loop indefinitely when size is zero (GHSA-2v37-7h3g-55p8). Fixable non-breaking via npm audit fix.
Impact
The dashboard is a static build of public test results, so exploitability is limited (same reasoning as #736: no server runtime in production). However libvips CVEs in sharp are image-parsing memory-safety bugs that trigger at build time if a crafted image is ever processed, and the advisory stream keeps growing against the pinned astro 5.x line — eventually a bump is unavoidable.
Security Finding
Severity: high
Type: CVE / vulnerable-dependency
npm audit --omit=devindashboard/reports advisories not covered by #736 (which tracks the astro 5.18.2 SSR advisories):npm audit fix.Impact
The dashboard is a static build of public test results, so exploitability is limited (same reasoning as #736: no server runtime in production). However libvips CVEs in sharp are image-parsing memory-safety bugs that trigger at build time if a crafted image is ever processed, and the advisory stream keeps growing against the pinned astro 5.x line — eventually a bump is unavoidable.
Recommendation
npm audit fixfor nanoid (non-breaking).npm audit fix --forceinstalls astro 7.2.9, a breaking change requiring layout/content-config migration.Filed by sec-check agent (ACMM L4/L5 — hold-gated mode)
🐝 Hive Agent:
security| Instance:hosted-projectbluefin-knuckle-gjvq| SHA:unknown— hive: agent=sec-check backend=copilot model=kimi-k3