Skip to content

fix(chessServer): npm audit fix + require express ^4.22.3, 0 vulnerabilities (Issue 4) - #238

Open
Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-chessserver-audit-fix
Open

Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-chessserver-audit-fix

Conversation

@Deepesh-Katudia

Copy link
Copy Markdown
Collaborator

Summary

Safe (no --force) npm audit fix for chessServer, plus raising the declared express floor. Takes npm audit from 14 findings to 0.

Type of Change

  • New feature
  • Bug fix
  • Refactor
  • Documentation update
  • Style/UI update
  • Performance improvement
  • Other (please specify): dependency / security update (Issue 4)

Key Changes

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed: npm audit = 0 findings after npm ci from the committed lockfile
  • All tests pass (clean npm ci then npm test)

Bugs Fixed (if applicable)

  • Clears the express / qs / body-parser / path-to-regexp findings.
  • Clears the engine.io / engine.io-client / socket.io-parser / socket.io-adapter / ws cluster without a direct socket.io bump.

TODO (Follow-up Work)

Additional Notes

Supersedes the chessServer lockfile commits on dependancyFix (regenerated fresh off current main instead of cherry-picked, since that branch is 26 commits behind). Independent of the other Issue 4 PRs.

sanjana1976 and others added 2 commits September 18, 2026 11:29
Safe, in-range lockfile refresh only; package.json is untouched. Run
until the lockfile stopped changing (the first pass alone is not always
enough).

The refresh moves express to 4.22.3, whose qs (~6.16.0) and
path-to-regexp are patched, so the express/qs/body-parser cluster
clears without an Express 5 migration. It also clears the
engine.io/socket.io-parser/ws cluster without bumping socket.io
directly.
Raises the declared floor to the first release that ships the patched
qs and path-to-regexp, so a regenerated lockfile cannot resolve back to
a vulnerable 4.21.x/4.22.2.
Copilot AI lite review requested due to automatic review settings September 18, 2026 16:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are limited to dependency/lockfile updates aligned with the stated goal of resolving audit findings without introducing application code changes.

Pull request overview

This PR updates chessServer dependencies via a safe (no --force) npm audit fix run and raises the declared minimum express version to prevent resolving to older vulnerable 4.x releases, bringing npm audit findings to zero for the service.

Changes:

  • Bump express dependency floor to ^4.22.3 in chessServer/package.json.
  • Refresh chessServer/package-lock.json to pull patched transitive versions (notably qs, path-to-regexp, engine.io/ws, js-yaml, morgan, and related packages).
File summaries
File Description
chessServer/package.json Raises the express minimum version to keep installs on a patched 4.x line.
chessServer/package-lock.json Lockfile refresh to resolve audited vulnerabilities to patched dependency versions.
Review details

Files not reviewed (1)

  • chessServer/package-lock.json: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ToldYO ToldYO left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good to merge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants