ryugraph's package.json currently pins:
"dependencies": {
"cmake-js": "^7.3.0",
...
}
cmake-js@7.4.0 (the latest version satisfying that range) depends on:
cmake-js@8.0.0 (released and available on npm) has already dropped npmlog entirely and bumped its tar dependency to ^7.5.6, which resolves clean under npm audit.
Every project depending on ryugraph — including ours (engramgraph) — inherits these 4 high-severity vulnerabilities + 3 deprecated-package warnings on a plain npm install, purely through this one pinned range. We worked around it locally with an npm overrides field, but that only helps when our own package.json is the install root — it doesn't propagate to anyone who installs our package (or any other ryugraph consumer) as a dependency or globally, so every downstream user still sees the same warnings.
Ask: would you consider bumping the cmake-js dependency range to ^8.0.0? From a quick look, cmake-js@8.0.0's public API surface used by ryugraph (native module build orchestration) appears unchanged, so this looks like it should be a safe, non-breaking bump — happy to be corrected if there's a reason ^7.3.0 was pinned intentionally, or to send a PR if that's easier.
Thanks for maintaining ryugraph!
ryugraph'spackage.jsoncurrently pins:cmake-js@7.4.0(the latest version satisfying that range) depends on:tar@^6.2.0→ resolves totar@6.2.1, which carries several high-severity path-traversal CVEs, fixed starting attar@7.5.11+ (e.g. GHSA-34x7-hfp2-rc4v, GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, GHSA-qffp-2rhf-9h96, GHSA-9ppj-qmqm-q256).npmlog@^6.0.2, which transitively pullsgaugeandare-we-there-yet— all three packages are marked deprecated/no-longer-supported upstream.cmake-js@8.0.0(released and available on npm) has already droppednpmlogentirely and bumped itstardependency to^7.5.6, which resolves clean undernpm audit.Every project depending on
ryugraph— including ours (engramgraph) — inherits these 4 high-severity vulnerabilities + 3 deprecated-package warnings on a plainnpm install, purely through this one pinned range. We worked around it locally with an npmoverridesfield, but that only helps when our own package.json is the install root — it doesn't propagate to anyone who installs our package (or any otherryugraphconsumer) as a dependency or globally, so every downstream user still sees the same warnings.Ask: would you consider bumping the
cmake-jsdependency range to^8.0.0? From a quick look,cmake-js@8.0.0's public API surface used byryugraph(native module build orchestration) appears unchanged, so this looks like it should be a safe, non-breaking bump — happy to be corrected if there's a reason^7.3.0was pinned intentionally, or to send a PR if that's easier.Thanks for maintaining ryugraph!