Vulnerabilites npm SDK Expo + uuid + xcode (18 packages, update lockstep Expo) #81
Labels
No labels
autopilot:pending-human
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-clarification
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/simpl-liste#81
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Contexte
Issue ouverte par run defenseur du 2026-04-30 listant 18 packages MEDIUM. Le milestone overnight
vuln-simpl-liste(2026-04-24) est marque 3/3 done, et trois overrides ont ete poses depuis :uuid@^11.1.1(PR #84, commit70211fc)postcss@^8.5.10(PR #80)@xmldom/xmldom@^0.8.13Un
npm auditlocal retourne 0 vulnerabilite. Les findings du 2026-04-30 sont vraisemblablement obsoletes (rapport pris avant le bump uuid 11.0.0 -> 11.1.1, ou outil qui flagge encore les chaines transitives malgre l'override).Travail a faire
defenseur-simpl-listepour produire un rapport frais (2026-05-07)tests/smoke.test.cjs(commitcfedde0) couvre toujours les overridesFichiers concernes
package.json—overrides(deja a jour pour uuid / xmldom / postcss / esbuild)package-lock.json— coherence avec overridestests/smoke.test.cjs— non-regression overridesSurface de test
tests/smoke.test.cjs(smoke uuid + package overrides, commit097d3f2)type:security, pastype:bug)Criteres d'acceptation
defenseur-simpl-liste-deps-npm-audit-simpl-liste-*npm audit: 0 vulnerabilite (deja vrai)tests/smoke.test.cjspasseOut of scope
expo-doctor-> issue separeetype:choreComplexite
Simple — operation de verification. Si rerun clean :
gh issue close.Note
Le path original (
npx expo install --fix+ upgrade SDK) reste un fallback si le rerun revele des findings non couverts par les overrides. Mais inutilement risque tant que les overrides suffisent.Analyse via
/analyze 81le 2026-05-07.Rerun defenseur 2026-05-08 — 0 findings
Rapport :
defenseur-simpl-liste_2026-05-08T01-35-19-829Z.jsonValidations :
npm audit: 0 vulnerabilitetests/smoke.test.cjs: 6/6 OK (uuid v3/v4/v5 + buffer args, valid package.json)Les 18 findings du run du 2026-04-30 etaient obsoletes — couverts depuis par les overrides poses dans le milestone
overnight-2026-04-24-vuln-simpl-listeet le bump uuid^11.0.0->^11.1.1(PR #84). Aucun PR additionnel necessaire.Closing as resolved.