cve-monitor: scanning /home/runner/work/ZeroAuth/ZeroAuth (dry-run=0)
cve-monitor: running npm audit --json in /home/runner/work/ZeroAuth/ZeroAuth
./scripts/cve-monitor.sh: line 84: echo: write error: Broken pipe
npm audit summary: {"info":0,"low":20,"moderate":13,"high":27,"critical":0,"total":60}
npm audit: 27 high/critical advisories found
- @nomicfoundation/hardhat-chai-matchers (high): see npm audit
- @nomicfoundation/hardhat-ethers (high): see npm audit
- @nomicfoundation/hardhat-network-helpers (high): see npm audit
- @nomicfoundation/hardhat-toolbox (high): see npm audit
- @nomicfoundation/hardhat-verify (high): see npm audit
- @typechain/hardhat (high): see npm audit
- adm-zip (high): adm-zip: Crafted ZIP file triggers 4GB memory allocation
- axios (high): Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
- bfj (high): see npm audit
- brace-expansion (high): brace-expansion: Zero-step sequence causes process hang and memory exhaustion
- fast-uri (high): fast-uri vulnerable to path traversal via percent-encoded dot segments
- form-data (high): form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- hardhat (high): see npm audit
- hardhat-gas-reporter (high): see npm audit
- immutable (high): Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
- js-yaml (high): JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
- jsonpath (high): see npm audit
- lodash (high): lodash vulnerable to Code Injection via `_.template` imports key names
- nodemailer (high): Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
- path-to-regexp (high): path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
- picomatch (high): Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
- serialize-javascript (high): Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
- solidity-coverage (high): see npm audit
- tmp (high): tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
- underscore (high): Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
- undici (high): Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
- ws (high): ws: Uninitialized memory disclosure
cve-monitor: osv-scanner not installed on this runner; skipping
::warning::osv-scanner not found — npm audit only. See C-032 setup notes.
cve-monitor: at least one HIGH or CRITICAL CVE found — failing
Nightly CVE monitor — high/critical finding
Run: https://github.com/zeroauth-dev/ZeroAuth/actions/runs/30680533075
Workflow:
CVE MonitorCommit: e307919
Closes audit-findings.md C-14 instrumentation; see
docs/plan/bfsi-v1/04-commits.mdcommit C-032 for context.Scanner output