Skip to main content

Security Audit Log

Dependency Vulnerabilities Assessment

Last Updated: 2026-02-16

Current Status

Moderate Severity Issues (Dev Dependencies Only)

Package: lodash, chevrotain, hono Source: Prisma dev tooling (@prisma/dev) Severity: Moderate Risk Level: LOW (Development dependencies, not exposed to production) Details:
  • Lodash: Prototype Pollution in _.unset and _.omit
  • Chevrotain: Transitive dependency via Prisma
  • Hono: Multiple vulnerabilities (XSS, cache control bypass, IP validation)
Mitigation:
  1. These packages are NOT included in production build
  2. Used only by Prisma CLI for migrations and code generation
  3. Production runtime uses @prisma/client (no vulnerabilities)
  4. Development environments are not exposed to external traffic
Action Plan:
  • ✅ Verified vulnerabilities are dev-only
  • ✅ Documented in security audit log
  • 🔄 Monitor for Prisma updates that resolve transitive dependencies
  • 🔄 Schedule monthly dependency audits
Next Review: 2026-03-16

Widget Dependencies

Status: ✅ No vulnerabilities detected Last Audit: 2026-02-16

Continuous Monitoring

Automated Checks

  • Set up GitHub Dependabot alerts
  • Configure automated security scanning in CI/CD
  • Enable npm audit in pre-commit hooks

Manual Review Schedule

  • Monthly: Full npm audit review
  • Quarterly: Update all dependencies to latest stable versions
  • Annually: External security audit

Version History

DateAuditorCriticalHighModerateLow
2026-02-16System008 (dev)0