mirror of
https://github.com/tiennm99/store-scraper-bot.git
synced 2026-10-11 03:13:50 +00:00
- pin form-data/qs/tough-cookie via package.json overrides; clears 3 of 4 Dependabot alerts (request SSRF risk-accepted, no upstream fix) - add GitHub Actions CI (lint + syntax check) on push/PR - add /settings and /setdayswarning to setMyCommands - new npm run describe sets bot profile description via Bot API - README: drop stale preview warning, add Operations section
3.2 KiB
3.2 KiB
phase, title, status, priority, effort, dependencies
| phase | title | status | priority | effort | dependencies |
|---|---|---|---|---|---|
| 1 | Dependabot overrides + audit | completed | P1 | 30m |
Phase 1: Dependabot overrides + audit
Overview
All 4 open alerts come transitively from app-store-scraper@0.18.0 → request@2.88.2. The request lib is abandoned (no patched version), but its transitive deps qs, form-data, tough-cookie have patches. Use npm overrides to force-pin the patched versions; accept the unfixable request SSRF advisory.
Context (from preflight)
app-store-scraper@0.18.0 (latest; still pulls request)
└─ request@2.88.2 (abandoned — SSRF GHSA, no fix)
├─ form-data@2.3.3 → patch to ^2.5.4 (CRITICAL: unsafe random boundary)
├─ qs@6.5.5 → patch to ^6.14.1 (DoS via memory exhaustion)
└─ tough-cookie@2.5.0 → patch to ^4.1.3 (Prototype Pollution)
google-play-scraper@10.1.2
└─ tough-cookie@4.1.4 (already patched, no action)
The request SSRF alert has fixed_in: null — no upstream fix. Risk: low — we only call known endpoints (itunes.apple.com, play.google.com); no user-controlled URLs reach request. Document + dismiss in GitHub UI as "won't fix / risk-accepted".
Architecture
package.json overrides field is npm's documented mechanism for forcing transitive dep versions. Apply at the top level (no nesting) — both request and google-play-scraper should use the patched versions.
Related Code Files
Modify
package.json— addoverridesblockpackage-lock.json— regenerate
Implementation Steps
- Add
overridestopackage.json:Carets so future patch bumps flow through."overrides": { "form-data": "^2.5.4", "qs": "^6.14.1", "tough-cookie": "^4.1.3" } - Run
npm installto regeneratepackage-lock.json. - Run
npm audit— expect only therequestSSRF alert remaining (unfixable). Everything else should clear. npm ls form-data qs tough-cookie— confirm overridden versions are in the tree.npm run lintto verify no incidental break.- Open GitHub Dependabot UI and dismiss the
requestSSRF alert: "risk accepted, no user-controlled URLs reachrequest".
Success Criteria
npm auditshows 0 vulnerabilities except the unfixablerequestSSRFnpm ls form-datashows^2.5.4npm ls qsshows^6.14.1npm ls tough-cookieshows^4.1.3everywhere- GitHub Dependabot page shows 0 open alerts (or only the dismissed
requestone) - Bot smoke-run on Vercel preview deploy still works
Risk Assessment
- Override breaks app-store-scraper: lib's pinned
qs@~6.5.2could rely on old behavior.qs@6.5 → 6.14is minor under semver butqshas had behavior tweaks (parameter parsing). Mitigation: smoke-test/checkappagainst a real Apple app after install. If broken, narrow override to a patched 6.5.x line if one exists; else vendor a minimal apple-scraper using nativefetch. - form-data 2.3 → 2.5 bump: patch-level under semver. Same mitigation.
requestSSRF unfixable: documented + dismissed. Long-term: replaceapp-store-scraperwith in-house fetch wrapper (out of scope).