Repository navigation
fix(stockfishServer): npm audit fix + require express ^4.22.3, 0 vulnerabilities (Issue 4) - #239
Open
Deepesh-Katudia wants to merge 2 commits into
Open
Deepesh-Katudia wants to merge 2 commits into
Deepesh-Katudia wants to merge 2 commits into
Conversation
Safe, in-range lockfile refresh only; package.json is untouched. Run until the lockfile stopped changing (the first pass alone is not always enough). The refresh moves express to 4.22.3, whose qs (~6.16.0) and path-to-regexp are patched, so the express/qs/body-parser cluster clears without an Express 5 migration. It also clears the engine.io/socket.io-parser/ws cluster without bumping socket.io directly.
Raises the declared floor to the first release that ships the patched qs and path-to-regexp, so a regenerated lockfile cannot resolve back to a vulnerable 4.21.x/4.22.2.
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved review issues remain, and the dependency updates address the reported vulnerabilities.
Pull request overview
Updates stockfishServer dependencies to remove audit vulnerabilities while retaining Express 4 compatibility.
Changes:
- Raises Express minimum to
^4.22.3. - Refreshes the lockfile with patched dependencies.
- Updates in-range Socket.IO and related packages.
File summaries
| File | Summary |
|---|---|
stockfishServer/package.json |
Raises the Express dependency floor. |
stockfishServer/package-lock.json |
Records updated secure dependency versions. |
Review details
Files not reviewed (1)
- stockfishServer/package-lock.json: Generated file
- Files reviewed: 1/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Safe (
no --force)npm audit fixforstockfishServer, plus raising the declared express floor. Takesnpm auditfrom 16 findings to 0.Type of Change
Key Changes
npm audit fix, re-run until the lockfile stopped changing). In-range updates only; resolves express to 4.22.3, which ships a patchedqs(~6.16.0) andpath-to-regexp.package.json:expressfloor raised to^4.22.3so a regenerated lockfile cannot resolve back to a vulnerable 4.x. One-line change.Testing
npm audit= 0 findings afternpm cifrom the committed lockfilenpm cithennpm test)Bugs Fixed (if applicable)
TODO (Follow-up Work)
Additional Notes
Supersedes the
stockfishServerlockfile commits ondependancyFix(regenerated fresh off current main instead of cherry-picked, since that branch is 26 commits behind). Independent of the other Issue 4 PRs.