Skip to content

Fix nanoid DoS advisory and stale hardcoded version strings - #2

Merged
RudrenduPaul merged 1 commit into
mainfrom
fix/security-audit-2026-08-24
Aug 25, 2026
Merged

RudrenduPaul merged 1 commit into
mainfrom
fix/security-audit-2026-08-24

Conversation

@Sourav-Nandy-ai

Copy link
Copy Markdown
Collaborator

Summary

  • Resolves a transitive high-severity nanoid DoS advisory (GHSA-2v37-7h3g-55p8, CWE-835, "custom generators can loop indefinitely when size is zero") pulled in via vitest -> vite -> postcss -> nanoid@<3.3.18. Added an npm overrides entry pinning nanoid to ^3.3.18. npm audit goes from 1 high vulnerability to 0.
  • Fixes a real bug: paceproof --version and the MCP server's reported serverInfo.version both hardcoded VERSION = "0.1.0" in src/cli.ts and src/mcp.ts, while package.json had already moved to 0.1.1 (published to npm as such). Added packages/cli-ts/src/version.ts as a single source of truth that reads the version out of package.json at runtime (via import.meta.url + fs.readFileSync, resolving correctly from both dist/ and src/ since both sit exactly one directory below the package root), and pointed cli.ts/mcp.ts at it instead of a duplicated literal.
  • Applied the same single-source-of-truth pattern to the Python package (packages/cli-py), which had the identical hardcoded-version duplication across pyproject.toml, __init__.py, and cli.py (values happened to still match, so no live bug there, but same latent drift risk). __init__.py now reads __version__ via importlib.metadata.version("paceproof-cli") from the installed distribution, with a safe fallback for an uninstalled/editable checkout; cli.py reuses that instead of its own hardcoded copy.

Verification

  • npm audit (packages/cli-ts): 0 vulnerabilities (was 1 high). npm ls nanoid confirms resolution to 3.3.18.
  • npm run build, npm run typecheck, npm run lint: all clean.
  • node dist/bin.js --version now correctly prints 0.1.1.
  • TypeScript test suite (vitest): 57/60 passing — the same 3 pre-existing Windows-only path-portability failures noted in the prior audit (resolveSafeOutputPath returning a drive-letter-prefixed path on Windows), unrelated to this change.
  • Python test suite (pytest): 52 passed, 0 failed, 0 skipped (previously 51 passed/1 skipped — the cross-language parity test was skipping because dist/bin.js didn't exist yet; it now builds and runs as part of this change).
  • ruff and mypy --strict remain clean.

Test plan

  • npm audit clean in packages/cli-ts
  • npm run build && npm run typecheck && npm run lint clean
  • node dist/bin.js --version prints 0.1.1
  • npm test (vitest) — 57/60, same pre-existing Windows-only failures as before this change
  • pytest in packages/cli-py — 52 passed

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com

https://claude.ai/code/session_01QyJoCc6YtjnErv6HKa6NPu

- Add npm override pinning nanoid to ^3.3.18, resolving the transitive
  high-severity DoS advisory (GHSA-2v37-7h3g-55p8, CWE-835) pulled in via
  vitest -> vite -> postcss -> nanoid. `npm audit` now reports 0
  vulnerabilities (was 1 high).
- Fix `paceproof --version` and the MCP server both misreporting the
  published 0.1.1 package as 0.1.0: both read from a hardcoded VERSION
  constant instead of package.json. Added src/version.ts as a single
  source of truth that reads the version out of package.json at runtime,
  and pointed cli.ts and mcp.ts at it.
- Applied the same single-source-of-truth fix to the Python package
  (packages/cli-py), which had the identical hardcoded-version pattern
  duplicated across pyproject.toml, __init__.py, and cli.py even though
  the values happened to still match -- __init__.py now reads the version
  via importlib.metadata from the installed distribution, and cli.py
  reuses it instead of its own hardcoded copy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QyJoCc6YtjnErv6HKa6NPu
@RudrenduPaul
RudrenduPaul merged commit fc98b7d into main Aug 25, 2026
7 checks passed
@RudrenduPaul
RudrenduPaul deleted the fix/security-audit-2026-08-24 branch August 25, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants