Documentation dependency follow-ups
The documentation toolchain is separate from application dependencies and from running Shipyard services. Dependencies are pinned in the lockfile; upgrades should include a clean install, full build, model checks and browser review.
Audit on 6 October 2026
Section titled “Audit on 6 October 2026”An npm audit identified an unpatched stack-exhaustion denial-of-service advisory in braces 3.0.3, reached through LikeC4 → vite-plugin-singlefile → micromatch. The registry’s latest braces release was still 3.0.3. Npm reports four high-severity affected packages along this one dependency chain; they are not four independently discovered application vulnerabilities.
The model/build inputs are repository-controlled, the generated site is served on loopback, and CI has a bounded timeout with no runtime deployment credentials. These conditions limit exposure; they do not establish that the advisory is fixed or that the site has had a security audit. Do not accept arbitrary uploaded build input or expose a development server publicly.
A separate CSS-selector parser advisory was addressed with the explicit postcss-selector-parser 7.1.6 override. The full docs build is the compatibility check; remove the override once upstream dependencies resolve to a patched version naturally.
Follow-up
Section titled “Follow-up”Check the upstream dependency chain for a patched release before broad hosting or a future toolchain update. Do not apply npm audit fix --force blindly: its suggestion in this run included downgrading major tooling. Reconsider the architecture renderer if an acceptable maintained dependency path does not emerge.
Run npm audit to refresh this observation. Audit dates and counts should be updated from actual results, not assumed from the lockfile alone.