Skip to content

fix(deps): take the nanoid patch that is failing the audit gate - #44

Merged
bgard68 merged 1 commit into
mainfrom
fix/nanoid-advisory
Aug 17, 2026
Merged

fix(deps): take the nanoid patch that is failing the audit gate#44
bgard68 merged 1 commit into
mainfrom
fix/nanoid-advisory

Conversation

@bgard68

@bgard68 bgard68 commented Aug 17, 2026

Copy link
Copy Markdown
Owner

The gate has been red since at least 2026-08-13, and only on audit:

GATE FAILED:
  - audit

Everything else passed — the probe suite included (3 of 3 probes caught). The single finding is GHSA-2v37-7h3g-55p8, high severity: nanoid's custom generators can loop indefinitely when size is zero.

nanoid is transitive (via vite), so there's no direct dependency to bump — npm audit fix resolves it inside the lock file alone.

nanoid 3.3.16 → 3.3.18. Three lines, one package, nothing else moved.

Same advisory that was blocking the sibling ToDoApp frontend, fixed there by ToDoApp#123.

Why this matters beyond the advisory

This blocks #41 and #43. Both are dependency bumps that cannot merge while a required gate fails for a reason unrelated to either of them — so one transitive CVE has held up the whole queue for days.

Verification

  • npm audit0 vulnerabilities
  • npm run typecheck → clean
  • 498 tests across 49 files pass

One caveat worth recording: the suite must be run from a path containing no # character. Vite refuses to resolve a project root with one and fails all 49 files for reasons entirely unrelated to the code — which looks exactly like a real regression if you don't read the warning line.

🤖 Generated with Claude Code

The gate has been red since at least 2026-08-13, and only on `audit`:

  GATE FAILED:
    - audit

Everything else passed - the probe suite included, 3 of 3 caught. The single
finding is GHSA-2v37-7h3g-55p8, high severity: nanoid's custom generators can
loop indefinitely when size is zero. nanoid is transitive (via vite), so there
is no direct dependency to bump; `npm audit fix` resolves it inside the lock
file alone.

nanoid 3.3.16 -> 3.3.18. Three lines, one package, nothing else moved.

This is the same advisory that was blocking the sibling ToDoApp frontend, fixed
there by ToDoApp#123.

Blocks #41 and #43: both are dependency bumps that cannot be merged while a
required gate is failing for a reason unrelated to either of them.

Verified locally: npm audit reports 0 vulnerabilities, typecheck is clean, and
all 498 tests across 49 files pass. Note the suite must be run from a path with
no '#' character - Vite refuses to resolve a project root containing one, which
fails all 49 files for reasons that have nothing to do with the code.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@bgard68
bgard68 merged commit 02ab7e0 into main Aug 17, 2026
4 checks passed
@bgard68
bgard68 deleted the fix/nanoid-advisory branch August 17, 2026 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant