Repository navigation
fix(chessServer): npm audit fix + require express ^4.22.3, 0 vulnerabilities (Issue 4) - #238
Open
Deepesh-Katudia wants to merge 2 commits into
Open
Deepesh-Katudia wants to merge 2 commits into
Deepesh-Katudia wants to merge 2 commits into
Conversation
Safe, in-range lockfile refresh only; package.json is untouched. Run until the lockfile stopped changing (the first pass alone is not always enough). The refresh moves express to 4.22.3, whose qs (~6.16.0) and path-to-regexp are patched, so the express/qs/body-parser cluster clears without an Express 5 migration. It also clears the engine.io/socket.io-parser/ws cluster without bumping socket.io directly.
Raises the declared floor to the first release that ships the patched qs and path-to-regexp, so a regenerated lockfile cannot resolve back to a vulnerable 4.21.x/4.22.2.
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The changes are limited to dependency/lockfile updates aligned with the stated goal of resolving audit findings without introducing application code changes.
Pull request overview
This PR updates chessServer dependencies via a safe (no --force) npm audit fix run and raises the declared minimum express version to prevent resolving to older vulnerable 4.x releases, bringing npm audit findings to zero for the service.
Changes:
- Bump
expressdependency floor to^4.22.3inchessServer/package.json. - Refresh
chessServer/package-lock.jsonto pull patched transitive versions (notablyqs,path-to-regexp,engine.io/ws,js-yaml,morgan, and related packages).
File summaries
| File | Description |
|---|---|
| chessServer/package.json | Raises the express minimum version to keep installs on a patched 4.x line. |
| chessServer/package-lock.json | Lockfile refresh to resolve audited vulnerabilities to patched dependency versions. |
Review details
Files not reviewed (1)
- chessServer/package-lock.json: Generated file
- Files reviewed: 1/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Safe (
no --force)npm audit fixforchessServer, plus raising the declared express floor. Takesnpm auditfrom 14 findings to 0.Type of Change
Key Changes
npm audit fix, re-run until the lockfile stopped changing). In-range updates only; resolves express to 4.22.3, which ships a patchedqs(~6.16.0) andpath-to-regexp.package.json:expressfloor raised to^4.22.3so a regenerated lockfile cannot resolve back to a vulnerable 4.x. One-line change.Testing
npm audit= 0 findings afternpm cifrom the committed lockfilenpm cithennpm test)Bugs Fixed (if applicable)
TODO (Follow-up Work)
Additional Notes
Supersedes the
chessServerlockfile commits ondependancyFix(regenerated fresh off current main instead of cherry-picked, since that branch is 26 commits behind). Independent of the other Issue 4 PRs.