Documentation Gap
SECURITY.md's "Known unpatched dependency advisories" section (added by #994, commit 17d67c3 on 2026-10-03T22:36Z) was accurate when written but went stale within hours:
- Count drifted: it says "
npm audit currently reports 34 high-severity packages". At main @900592b, npm audit --json reports 29 high (0 critical/moderate/low).
- "No upgrade to apply" is no longer true for http-cache-semantics: the section claims both packages "are already at their newest published version, so there is no upgrade to apply and Dependabot has nothing to offer."
http-cache-semantics@4.3.0 was published to npm on 2026-10-04T02:56:05Z, ~4 hours after the section merged. Advisory GHSA-ch52-4w7c-c8xp covers <=4.2.0, and upstream (kornelski/http-cache-semantics) landed the fix commits on 2026-10-03/04 ("Fix: handle Vary wildcard and inherited headers"). npm audit now reports fixAvailable: true for it, and npm audit fix --dry-run resolves to 4.3.0 without --force.
- The "Do not run
npm audit fix --force" warning's rationale is stale: it rests on "No patched version exists for either package" — a patched version now exists for http-cache-semantics. (The braces half remains accurate: braces 3.0.3 is still the latest published version and fixAvailable is still false for GHSA-vfj7-8cjw-p6xm.)
The section's own closing line anticipates this: "Remove this section once upstream publishes fixes and the dependency tree picks them up."
Impact
Contributors and security reviewers reading SECURITY.md get an outdated audit count and are told no fix exists when a plain npm audit fix now clears one of the two root advisories; anyone following the doc literally will leave a fixable advisory in the tree.
Recommendation
- Run
npm audit fix to pick up http-cache-semantics@4.3.0 (lockfile-only change; no --force needed), then re-run npm audit and update the section: corrected count, remove the http-cache-semantics row, keep the braces row and the --force warning scoped to braces only.
Verification evidence (per command-verification policy)
npm audit --json at main @900592b (2026-10-04T08:25Z): 29 high; http-cache-semantics fixAvailable: true, range <=4.2.0; braces fixAvailable: false, range <=3.0.3.
- npm registry:
http-cache-semantics latest = 4.3.0 (time["4.3.0"] = 2026-10-04T02:56:05.593Z); braces latest = 3.0.3.
- GitHub Advisory API for GHSA-ch52-4w7c-c8xp: vulnerable range
<= 4.2.0, updated 2026-10-02T22:36:44Z.
npm audit fix --dry-run: adds http-cache-semantics 4.3.0 (no --force required).
- Upstream commits: kornelski/http-cache-semantics 9fb520b "Fix: handle Vary wildcard and inherited headers" (2026-10-03), release tagged 2026-10-04T02:54Z.
Filed by guide agent (ACMM L4 — issues-only mode)
🐝 Hive Agent: guide | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown
— hive: agent=guide backend=copilot model=kimi-k3 copilot=1.0.88
Documentation Gap
SECURITY.md's "Known unpatched dependency advisories" section (added by #994, commit 17d67c3 on 2026-10-03T22:36Z) was accurate when written but went stale within hours:
npm auditcurrently reports 34 high-severity packages". At main @900592b,npm audit --jsonreports 29 high (0 critical/moderate/low).http-cache-semantics@4.3.0was published to npm on 2026-10-04T02:56:05Z, ~4 hours after the section merged. Advisory GHSA-ch52-4w7c-c8xp covers<=4.2.0, and upstream (kornelski/http-cache-semantics) landed the fix commits on 2026-10-03/04 ("Fix: handle Vary wildcard and inherited headers").npm auditnow reportsfixAvailable: truefor it, andnpm audit fix --dry-runresolves to 4.3.0 without--force.npm audit fix --force" warning's rationale is stale: it rests on "No patched version exists for either package" — a patched version now exists for http-cache-semantics. (The braces half remains accurate: braces 3.0.3 is still the latest published version andfixAvailableis still false for GHSA-vfj7-8cjw-p6xm.)The section's own closing line anticipates this: "Remove this section once upstream publishes fixes and the dependency tree picks them up."
Impact
Contributors and security reviewers reading SECURITY.md get an outdated audit count and are told no fix exists when a plain
npm audit fixnow clears one of the two root advisories; anyone following the doc literally will leave a fixable advisory in the tree.Recommendation
npm audit fixto pick uphttp-cache-semantics@4.3.0(lockfile-only change; no--forceneeded), then re-runnpm auditand update the section: corrected count, remove the http-cache-semantics row, keep the braces row and the--forcewarning scoped to braces only.Verification evidence (per command-verification policy)
npm audit --jsonat main @900592b (2026-10-04T08:25Z): 29 high; http-cache-semanticsfixAvailable: true, range<=4.2.0; bracesfixAvailable: false, range<=3.0.3.http-cache-semanticslatest = 4.3.0 (time["4.3.0"] = 2026-10-04T02:56:05.593Z);braceslatest = 3.0.3.<= 4.2.0, updated 2026-10-02T22:36:44Z.npm audit fix --dry-run: adds http-cache-semantics 4.3.0 (no--forcerequired).Filed by guide agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
guide| Instance:hosted-available-lke648397-260827-5n31| SHA:unknown— hive: agent=guide backend=copilot model=kimi-k3 copilot=1.0.88