Skip to content

Patch vulnerable runtime and proof dependencies - #103

Merged
noeltock merged 2 commits into
mainfrom
codex/security-maintenance-0914
Sep 14, 2026
Merged

noeltock merged 2 commits into
mainfrom
codex/security-maintenance-0914

Conversation

@noeltock

@noeltock noeltock commented Sep 14, 2026

Copy link
Copy Markdown
Member

Patch the vulnerable colour and ZIP dependencies and update the affected test/proof tooling.

  • Update Vitest to 4.1.11 and WordPress env to 11.15.0, with matching optional peer, proof pins and setup instructions.
  • Refresh the root lock to colord 2.10.0 and adm-zip 0.6.1. Patch adm-zip in the generated-plugin lock too, advance its lock-template revision and assert the patched version in the existing test.

Runtime Gutenberg/React versions, Wesper and supported Node versions are unchanged.

Validation at 7aa2ffe: full CI passed on Node 20.19.0, 22.13.0 and 24.0.0, including packed CLI smoke checks; package-consumer archive builds and WordPress 7.1 automated acceptance passed. Four focused pin/lock tests passed locally. The offline 63-fixture conversion benchmark remains at score 31, with zero invalid outputs and 66 fallbacks.

The runtime-only lockfile audit is clean. The full audit fell from 29 to 24 affected packages; the targeted findings are absent. Remaining findings are in the OpenTelemetry/Sentry, Puppeteer/Lighthouse/extract-zip and Playground/Express tooling chains. No model benchmark or npm release was performed.

@noeltock
noeltock merged commit d092ef3 into main Sep 14, 2026
9 checks passed
@noeltock
noeltock deleted the codex/security-maintenance-0914 branch September 14, 2026 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant