fix(deps): bump source-map-js to 1.2.2 for GHSA-68fv-2mgg-jv7q - #619
Merged
Merged
Conversation
npm audit --audit-level=high reports one high-severity advisory: source-map-js allows event-loop denial of service through indexed source-map section offsets. It is a dev-only transitive dependency (via vite/postcss) and is present at every protocol pin, so the hourly Update Mouse Protocol workflow fails at its audit step: the app stays pinned to 0.24.0 even though 0.26.0 is published, which keeps the newly merged AJAZZ, Redragon M690 PRO and Lamzu Paro Aurora drivers unreachable in the panel. npm audit fix moves source-map-js 1.2.1 -> 1.2.2. Audit is clean, npm run check passes 290/290 and npm run size stays inside the budget.
Deploying openmouse with
|
| Latest commit: |
fb656e8
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://117f51d8.openmouse.pages.dev |
| Branch Preview URL: | https://fix-source-map-js-advisory.openmouse.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One high-severity advisory is open on
main: source-map-js allows event-loop DoS through indexed source-map section offsets (GHSA-68fv-2mgg-jv7q). It is a dev-only transitive dependency (via vite/postcss), and it is present at every protocol pin — so it is not caused by the protocol bump.Why this blocks more than it looks.
.github/workflows/update-protocol.ymlrunsnpm audit --audit-level=highafter installing the latest@openmouse/protocol, and that step fails, so the hourly job never commits.mainis therefore stuck on0.24.0while 0.26.0 is published, and the drivers merged since (AJAZZ AJ179 PRO, Redragon M690 PRO, Lamzu Paro Aurora, plus the X11-on-Bridge and PRO X Wireless format fixes) are unreachable in the panel.npm audit fixmovessource-map-js1.2.1 → 1.2.2, a lockfile-only change.Verified locally with the workflow's own gates at pin 0.26.0:
npm audit --audit-level=high→ 0 vulnerabilitiesnpm run check→ 290/290 tests, build cleannpm run size→ CSS 100%, JS 100% of budget (passes; note the JS budget has only ~0.9 KB of headroom left)