enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

enable audit for npm i -g - #23

Closed
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix
Closed

enable audit for npm i -g#23
brody2consult wants to merge 1 commit into
npm:latestfrom
brody2consult:global-audit-fix

Conversation

@brody2consult

Copy link
Copy Markdown

I think npm i -g should show if there are any possible security vulnerabilities from the dependencies, if I would do npm i -g cordova@7 for example.

(In comparison: npm i cordova@7 shows the following message at the end: found 55 vulnerabilities (4 low, 45 moderate, 6 high))

These changes pass Travis CI on my fork. I wonder if this behavior should be covered more deeply?

@brody2consult
brody2consult requested a review from a team as a code ownerJuly 19, 2018 01:36
@brody2consult

Copy link
Copy Markdown
Author

Closing because I think this does not work right. If I test with my local version of npm with this change included: ./node_modules/.bin/npm i -g cordova@7

I get the following output:

npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
/Users/brodybits/.nvs/node/10.7.0-test1/x64/bin/cordova -> /Users/brodybits/.nvs/node/10.7.0-test1/x64/lib/node_modules/cordova/bin/cordova
+ cordova@7.1.0
added 628 packages from 792 contributors in 70.187s
found 0 vulnerabilities

But cordova@7.1.0 (cordova-cli@7.10.0) uses cordova-lib@7.1.0 which has known vulnerabilities in its dependencies.

I continue to think that npm should check audit upon npm i -g, will investigate further whenever I can. My apologies for not testing before raising this PR.

koralle pushed a commit to koralle/npm-cli that referenced this pull request Feb 11, 2026
* feat: add optimize command
Build a optimized Hono class.
* chore: add esbuild to dependencies
* feat(optimize): try to find entry files from default candidates if not specified
* refactor(optimize): sourcemap is not needed
* refactor(optimize): Assign the serialized code to a variable once, even in JavaScript
* chore: add "vitest/globals" to types in tsconfig.json
* test(optimize): add tests
* test(optimize): import vitest explicitly
* feat(optimize): changed specifications to export bundled files.
* Update README.md
* refactor(optimize): Remove unused code
* refactor(optimize): write files directly from `esbuild.build`
* Update README.md
* feat(optimize): add minify option
* feat(optimize): add stat to output
* refactor(optimize): improve output messages
* refactor(optimize): improve output messages
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
---------
Co-authored-by: Yusuke Wada <yusuke@kamawada.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
)
* refactor: replace manual urlencoded() with reqwest .query() builder
Remove duplicate hand-rolled urlencoded() functions from workflows.rs
and calendar.rs. All query parameters are now passed via reqwest's
.query() API, which handles percent-encoding correctly and completely.
* fix: percent-encode path parameters to prevent path traversal
Use percent_encoding::utf8_percent_encode for calendar_id, cal.id,
message_id, and file_id before interpolating into URL path segments.
Addresses code review feedback on security regression.
* fix: add shared URL safety helpers for path params
Add encode_path_segment() for single-segment IDs and
validate_resource_name() for multi-segment resource names.
encode_path_segment: percent-encodes all non-alphanumeric chars,
used for calendar IDs, file IDs, and message IDs.
validate_resource_name: rejects path traversal (..) and control
chars while preserving intentional / structure, used for Chat
space names, task list IDs, and subscription names. Returns clear
error messages for LLM callers.
* test: add AI edge case tests for URL safety helpers
Cover query/fragment injection, double-encoding, unicode, spaces,
path traversal via encoding, control chars (CR/tab), and clear
error message assertions for LLM callers.
* fix: warn on stderr when API calls fail silently
- Daily briefing calendar events fetch
- Daily briefing tasks fetch
- Daily summary calendar events fetch
- Daily summary unread email count fetch
Addresses PR review feedback about confusing silent failures,
especially for LLM callers that cannot see visual cues.
* fix: harden input validation for AI/LLM callers
- Add src/validate.rs with validate_safe_output_dir, validate_msg_format,
and validate_safe_dir_path helpers
- Validate --output-dir against path traversal in gmail +watch and
events +subscribe
- Validate --msg-format against allowlist in gmail +watch
- Validate --dir against path traversal in script +push
- Add clap value_parser constraint for --msg-format
- Document input validation patterns in AGENTS.md
Closesnpm#23
* chore: add changesets for PR npm#21 commits
* test: add comprehensive test coverage for input validation handlers
* docs: document input validation and URL safety patterns in AGENTS.md and CONTRIBUTING.md
* fix: address PR review comments — reject ?/# in resource names, validate subscription arg, remove redundant validate_msg_format
* fix: store validated PathBuf, remove dead code, delete duplicate SubscribeConfig
Addresses review comments:
- Store validated PathBuf from validate_safe_output_dir instead of
discarding it (output_dir is now Option<PathBuf>)
- Remove duplicate SubscribeConfig from events/mod.rs
- Delete unused validate_msg_format (clap value_parser handles this)
- Remove all #[allow(dead_code)] annotations
* fix: per-segment traversal check in validate_resource_name, fix docs
* fix: harden security validation and deduplicate logic
---------
Co-authored-by: jpoehnelt-bot <jpoehnelt-bot@users.noreply.github.com>
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 30, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 25, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 4, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brody2consult