From e25e773bf309b96c93c8035e3a08bb6d139cd37d Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 11 Apr 2026 02:22:16 +0000 Subject: [PATCH] chore(deps): bump basic-ftp from 5.2.1 to 5.2.2 (#47) * chore(deps): bump basic-ftp from 5.2.1 to 5.2.2 Bumps [basic-ftp](https://github.com/patrickjuchli/basic-ftp) from 5.2.1 to 5.2.2. - [Release notes](https://github.com/patrickjuchli/basic-ftp/releases) - [Changelog](https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md) - [Commits](https://github.com/patrickjuchli/basic-ftp/compare/v5.2.1...v5.2.2) --- updated-dependencies: - dependency-name: basic-ftp dependency-version: 5.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] * fix: unblock dependency audit for pr 47 --------- Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Xi Xu --- package-lock.json | 14 +++++------ package.json | 2 +- tests/security-governance.test.cjs | 39 ++++++++++++++++++++++++++++++ 3 files changed, 47 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index 971135b..0006bcb 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13,7 +13,7 @@ "@types/turndown": "^5.0.6", "@xmldom/xmldom": "^0.9.9", "archiver": "^7.0.1", - "axios": "^1.14.0", + "axios": "^1.15.0", "bcrypt": "^6.0.0", "busboy": "^1.6.0", "civkit": "^0.9.1-a38f565", @@ -1874,9 +1874,9 @@ } }, "node_modules/axios": { - "version": "1.14.0", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.14.0.tgz", - "integrity": "sha512-3Y8yrqLSwjuzpXuZ0oIYZ/XGgLwUIBU3uLvbcpb0pidD9ctpShJd43KSlEEkVQg6DS0G9NKyzOvBfUtDKEyHvQ==", + "version": "1.15.0", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.15.0.tgz", + "integrity": "sha512-wWyJDlAatxk30ZJer+GeCWS209sA42X+N5jU2jy6oHTp7ufw8uzUTVFBX9+wTfAlhiJXGS0Bq7X6efruWjuK9Q==", "license": "MIT", "dependencies": { "follow-redirects": "^1.15.11", @@ -2019,9 +2019,9 @@ ] }, "node_modules/basic-ftp": { - "version": "5.2.1", - "resolved": "https://registry.npmjs.org/basic-ftp/-/basic-ftp-5.2.1.tgz", - "integrity": "sha512-0yaL8JdxTknKDILitVpfYfV2Ob6yb3udX/hK97M7I3jOeznBNxQPtVvTUtnhUkyHlxFWyr5Lvknmgzoc7jf+1Q==", + "version": "5.2.2", + "resolved": "https://registry.npmjs.org/basic-ftp/-/basic-ftp-5.2.2.tgz", + "integrity": "sha512-1tDrzKsdCg70WGvbFss/ulVAxupNauGnOlgpyjKzeQxzyllBLS0CGLV7tjIXTK3ZQA9/FBEm9qyFFN1bciA6pw==", "license": "MIT", "engines": { "node": ">=10.0.0" diff --git a/package.json b/package.json index 11f9d29..8fbda50 100644 --- a/package.json +++ b/package.json @@ -27,7 +27,7 @@ "@types/turndown": "^5.0.6", "@xmldom/xmldom": "^0.9.9", "archiver": "^7.0.1", - "axios": "^1.14.0", + "axios": "^1.15.0", "bcrypt": "^6.0.0", "busboy": "^1.6.0", "civkit": "^0.9.1-a38f565", diff --git a/tests/security-governance.test.cjs b/tests/security-governance.test.cjs index 5c5d85d..09f2b7a 100644 --- a/tests/security-governance.test.cjs +++ b/tests/security-governance.test.cjs @@ -9,6 +9,23 @@ function read(relativePath) { return fs.readFileSync(path.join(projectRoot, relativePath), "utf8"); } +function compareVersions(left, right) { + const leftParts = left.split(".").map(Number); + const rightParts = right.split(".").map(Number); + const length = Math.max(leftParts.length, rightParts.length); + + for (let index = 0; index < length; index += 1) { + const leftValue = leftParts[index] ?? 0; + const rightValue = rightParts[index] ?? 0; + + if (leftValue !== rightValue) { + return leftValue - rightValue; + } + } + + return 0; +} + test("package.json exposes the security audit script and excludes removed cloud dependencies", () => { const packageJson = JSON.parse(read("package.json")); @@ -55,3 +72,25 @@ test("lodash is declared directly and lockfile avoids the vulnerable 4.17.23 rel /"node_modules\/lodash":\s*\{[\s\S]*?"version":\s*"4\.17\.23"/, ); }); + +test("security-sensitive dependency floors stay above blocked axios and basic-ftp releases", () => { + const packageJson = JSON.parse(read("package.json")); + const packageLock = JSON.parse(read("package-lock.json")); + const axiosRange = packageJson.dependencies.axios.replace(/^[^\d]*/, ""); + const lockedAxiosVersion = packageLock.packages["node_modules/axios"].version; + const lockedBasicFtpVersion = + packageLock.packages["node_modules/basic-ftp"].version; + + assert.ok( + compareVersions(axiosRange, "1.15.0") >= 0, + `Expected axios floor >= 1.15.0, received ${packageJson.dependencies.axios}`, + ); + assert.doesNotMatch( + lockedAxiosVersion, + /^1\.14\.0$/, + ); + assert.ok( + compareVersions(lockedBasicFtpVersion, "5.2.2") >= 0, + `Expected basic-ftp lock >= 5.2.2, received ${lockedBasicFtpVersion}`, + ); +});