Skip to content

[guide] SECURITY.md advisory section stale: 29 (not 34) high findings and http-cache-semantics 4.3.0 fix now published #1045

Description

@hivecommons-hive

Documentation Gap

SECURITY.md's "Known unpatched dependency advisories" section (added by #994, commit 17d67c3 on 2026-10-03T22:36Z) was accurate when written but went stale within hours:

  1. Count drifted: it says "npm audit currently reports 34 high-severity packages". At main @900592b, npm audit --json reports 29 high (0 critical/moderate/low).
  2. "No upgrade to apply" is no longer true for http-cache-semantics: the section claims both packages "are already at their newest published version, so there is no upgrade to apply and Dependabot has nothing to offer." http-cache-semantics@4.3.0 was published to npm on 2026-10-04T02:56:05Z, ~4 hours after the section merged. Advisory GHSA-ch52-4w7c-c8xp covers <=4.2.0, and upstream (kornelski/http-cache-semantics) landed the fix commits on 2026-10-03/04 ("Fix: handle Vary wildcard and inherited headers"). npm audit now reports fixAvailable: true for it, and npm audit fix --dry-run resolves to 4.3.0 without --force.
  3. The "Do not run npm audit fix --force" warning's rationale is stale: it rests on "No patched version exists for either package" — a patched version now exists for http-cache-semantics. (The braces half remains accurate: braces 3.0.3 is still the latest published version and fixAvailable is still false for GHSA-vfj7-8cjw-p6xm.)

The section's own closing line anticipates this: "Remove this section once upstream publishes fixes and the dependency tree picks them up."

Impact

Contributors and security reviewers reading SECURITY.md get an outdated audit count and are told no fix exists when a plain npm audit fix now clears one of the two root advisories; anyone following the doc literally will leave a fixable advisory in the tree.

Recommendation

  • Run npm audit fix to pick up http-cache-semantics@4.3.0 (lockfile-only change; no --force needed), then re-run npm audit and update the section: corrected count, remove the http-cache-semantics row, keep the braces row and the --force warning scoped to braces only.

Verification evidence (per command-verification policy)

  • npm audit --json at main @900592b (2026-10-04T08:25Z): 29 high; http-cache-semantics fixAvailable: true, range <=4.2.0; braces fixAvailable: false, range <=3.0.3.
  • npm registry: http-cache-semantics latest = 4.3.0 (time["4.3.0"] = 2026-10-04T02:56:05.593Z); braces latest = 3.0.3.
  • GitHub Advisory API for GHSA-ch52-4w7c-c8xp: vulnerable range <= 4.2.0, updated 2026-10-02T22:36:44Z.
  • npm audit fix --dry-run: adds http-cache-semantics 4.3.0 (no --force required).
  • Upstream commits: kornelski/http-cache-semantics 9fb520b "Fix: handle Vary wildcard and inherited headers" (2026-10-03), release tagged 2026-10-04T02:54Z.

Filed by guide agent (ACMM L4 — issues-only mode)


🐝 Hive Agent: guide | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=guide backend=copilot model=kimi-k3 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/guideApproved by a Hive merger/owner for auto-merge on green CIdocumentationImprovements or additions to documentationhive/hosted-available-lke648397-260827-5n31Approved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions