Skip to content

AP-10424 # npm audit fix - #284

Merged
kizaonline merged 1 commit into
masterfrom
AP-10424
Sep 22, 2026
Merged

kizaonline merged 1 commit into
masterfrom
AP-10424

Conversation

@kizaonline

@kizaonline kizaonline commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Requester Checklist

Please only check the items that you have actioned. Do not check items that are not applicable to your PR.

Implementation

  • Have you tested your implementation locally?
  • If applicable, has an appropriate changelog entry been added? Do not include if you are fixing/changing something that is only in the current release.
  • There are no warnings that have been suppressed unnecessarily
  • Have automated tests been added, or have related ones been updated to cover the change?
  • Have all OneBlink dependency updates been completed (eg apps / apps-react / types etc).
  • Have you ensured this change does not add unwanted dependencies?
  • If this PR contains a refactor, have relevant Jira testing tasks added?
  • Changes that will knowingly make the feature/bug incomplete have been commented with TODO and a description of what needs to be done to finish the feature/bug
  • Any changes made to public APIs have been reflected in the documentation
  • Have you isolated business logic where possible to allow for unit testing?

Logging and Debugging

  • Are the error messages, if any, informative?
  • Are there enough log events and are they written in a way that allows for easy debugging?
  • "Debugging" code removed
  • Front-end: No erroneous Console.WriteLines

Readability

  • All class, variable, property and method modifiers are provided with the smallest scope possible
  • New files, variables and functions are descriptive/comprehensible and named consistently.
  • There is no dead code (unreachable code)
  • There is no usage of magic numbers
  • There is no commented out code.
  • In hard-to-understand areas, comments exist and describe rationale or reasons for decisions in code

Security

  • All personal data inputs are checked (for the correct type, length/size, format, and range).
  • No sensitive information is logged or visible in a stacktrace
  • Are authorization and authentication handled correctly?
  • Is (user) input validated, sanitized, and escaped to prevent security attacks such as cross-site scripting or SQL injection?
  • Is data retrieved from external APIs or libraries checked for security issues?
  • Do API endpoints return appropriate status codes

Reviewer Guide

  • It is important that you understand the purpose of the PR.
  • You are encouraged to engage with the requestor if you do not understand any of the proposed code changes/additions/deletions.
  • Do you, the reviewer, understand what the code does? Do you think a specific expert, like a security expert or a usability expert, should look over the code before it can be accepted?
  • Is a framework, API, library, or service used that should not be used? Are there alternatives you could recommend?
  • Are there existing hooks/components/functions in the same code base that could be utilised?
  • When reviewing tests, attempt to identify missing edge cases that may be relevant to the proposed implementation
  • Ensure you check for:
    • Security
    • Scalability
    • Performance
    • Maintainability

Note

Low Risk
Lockfile-only dependency bumps with no app logic changes; minor risk is limited to dev builds/tests and transitive Express/qs behavior in local tooling.

Overview
Refreshes package-lock.json after npm audit fix (AP-10424), with no application source changes.

The lockfile pulls newer transitive runtime versions used by the CLI stack—express (4.22.3), body-parser, morgan, and qs (6.16.0) with updated side-channel helpers—addressing typical audit findings on HTTP/query parsing.

Dev/build dependencies move in step, mainly the Vite 8.3 toolchain (rolldown 1.2.9, lightningcss 1.33, @oxc-project/types) and vitest 4.1.11. WASM-related optional packages (@emnapi/*, @rolldown/binding-wasm32-wasi) drop from the tree while @rolldown/binding-android-arm-eabi is added.

Reviewed by Cursor Bugbot for commit ab00009. Bugbot is set up for automated code reviews on this repo. Configure here.

@kizaonline
kizaonline merged commit 3d953d4 into master Sep 22, 2026
4 checks passed
@kizaonline
kizaonline deleted the AP-10424 branch September 22, 2026 01:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant