Repository navigation
Fix nanoid DoS advisory and stale hardcoded version strings - #2
Merged
Merged
Conversation
- Add npm override pinning nanoid to ^3.3.18, resolving the transitive high-severity DoS advisory (GHSA-2v37-7h3g-55p8, CWE-835) pulled in via vitest -> vite -> postcss -> nanoid. `npm audit` now reports 0 vulnerabilities (was 1 high). - Fix `paceproof --version` and the MCP server both misreporting the published 0.1.1 package as 0.1.0: both read from a hardcoded VERSION constant instead of package.json. Added src/version.ts as a single source of truth that reads the version out of package.json at runtime, and pointed cli.ts and mcp.ts at it. - Applied the same single-source-of-truth fix to the Python package (packages/cli-py), which had the identical hardcoded-version pattern duplicated across pyproject.toml, __init__.py, and cli.py even though the values happened to still match -- __init__.py now reads the version via importlib.metadata from the installed distribution, and cli.py reuses it instead of its own hardcoded copy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QyJoCc6YtjnErv6HKa6NPu
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
nanoidDoS advisory (GHSA-2v37-7h3g-55p8, CWE-835, "custom generators can loop indefinitely when size is zero") pulled in viavitest -> vite -> postcss -> nanoid@<3.3.18. Added an npmoverridesentry pinningnanoidto^3.3.18.npm auditgoes from 1 high vulnerability to 0.paceproof --versionand the MCP server's reportedserverInfo.versionboth hardcodedVERSION = "0.1.0"insrc/cli.tsandsrc/mcp.ts, whilepackage.jsonhad already moved to0.1.1(published to npm as such). Addedpackages/cli-ts/src/version.tsas a single source of truth that reads the version out ofpackage.jsonat runtime (viaimport.meta.url+fs.readFileSync, resolving correctly from bothdist/andsrc/since both sit exactly one directory below the package root), and pointedcli.ts/mcp.tsat it instead of a duplicated literal.packages/cli-py), which had the identical hardcoded-version duplication acrosspyproject.toml,__init__.py, andcli.py(values happened to still match, so no live bug there, but same latent drift risk).__init__.pynow reads__version__viaimportlib.metadata.version("paceproof-cli")from the installed distribution, with a safe fallback for an uninstalled/editable checkout;cli.pyreuses that instead of its own hardcoded copy.Verification
npm audit(packages/cli-ts): 0 vulnerabilities (was 1 high).npm ls nanoidconfirms resolution to3.3.18.npm run build,npm run typecheck,npm run lint: all clean.node dist/bin.js --versionnow correctly prints0.1.1.resolveSafeOutputPathreturning a drive-letter-prefixed path on Windows), unrelated to this change.dist/bin.jsdidn't exist yet; it now builds and runs as part of this change).ruffandmypy --strictremain clean.Test plan
npm auditclean inpackages/cli-tsnpm run build && npm run typecheck && npm run lintcleannode dist/bin.js --versionprints0.1.1npm test(vitest) — 57/60, same pre-existing Windows-only failures as before this changepytestinpackages/cli-py— 52 passedCo-Authored-By: Claude Sonnet 5 noreply@anthropic.com
https://claude.ai/code/session_01QyJoCc6YtjnErv6HKa6NPu