Skip to content

fix(stockfishServer): npm audit fix + require express ^4.22.3, 0 vulnerabilities (Issue 4) - #239

Open
Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-stockfishserver-audit-fix
Open

Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-stockfishserver-audit-fix

Conversation

@Deepesh-Katudia

Copy link
Copy Markdown
Collaborator

Summary

Safe (no --force) npm audit fix for stockfishServer, plus raising the declared express floor. Takes npm audit from 16 findings to 0.

Type of Change

  • New feature
  • Bug fix
  • Refactor
  • Documentation update
  • Style/UI update
  • Performance improvement
  • Other (please specify): dependency / security update (Issue 4)

Key Changes

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed: npm audit = 0 findings after npm ci from the committed lockfile
  • All tests pass (clean npm ci then npm test)

Bugs Fixed (if applicable)

  • Clears the express / qs / body-parser / path-to-regexp findings.
  • Clears the engine.io / engine.io-client / socket.io-parser / socket.io-adapter / ws cluster without a direct socket.io bump.

TODO (Follow-up Work)

Additional Notes

Supersedes the stockfishServer lockfile commits on dependancyFix (regenerated fresh off current main instead of cherry-picked, since that branch is 26 commits behind). Independent of the other Issue 4 PRs.

sanjana1976 and others added 2 commits September 18, 2026 11:30
Safe, in-range lockfile refresh only; package.json is untouched. Run
until the lockfile stopped changing (the first pass alone is not always
enough).

The refresh moves express to 4.22.3, whose qs (~6.16.0) and
path-to-regexp are patched, so the express/qs/body-parser cluster
clears without an Express 5 migration. It also clears the
engine.io/socket.io-parser/ws cluster without bumping socket.io
directly.
Raises the declared floor to the first release that ships the patched
qs and path-to-regexp, so a regenerated lockfile cannot resolve back to
a vulnerable 4.21.x/4.22.2.
Copilot AI lite review requested due to automatic review settings September 18, 2026 16:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues remain, and the dependency updates address the reported vulnerabilities.

Pull request overview

Updates stockfishServer dependencies to remove audit vulnerabilities while retaining Express 4 compatibility.

Changes:

  • Raises Express minimum to ^4.22.3.
  • Refreshes the lockfile with patched dependencies.
  • Updates in-range Socket.IO and related packages.
File summaries
File Summary
stockfishServer/package.json Raises the Express dependency floor.
stockfishServer/package-lock.json Records updated secure dependency versions.
Review details

Files not reviewed (1)

  • stockfishServer/package-lock.json: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants