Repository navigation
Conversation
CI runs 'npm audit' as a required step, and the current lockfile fails it with 6 vulnerabilities (3 high, 2 moderate, 1 low), all in dev-tool transitive dependencies: - serialize-javascript <=7.0.4 (high, RCE + DoS advisories) via mocha - diff 5.0.0-5.2.1 (jsdiff DoS in parsePatch/applyPatch) via mocha - js-yaml 4.0.0-4.3.0 (quadratic-CPU DoS advisories) via eslint/mocha - brace-expansion (DoS family) via minimatch consumers - ajv <6.14.0 (ReDoS) via eslint None are fixable by 'npm audit fix' alone: even mocha@latest still pins vulnerable serialize-javascript/diff ranges. Add npm 'overrides' pinning each package to its patched line and regenerate the lockfile. Runtime dependencies are untouched — the diff is dev-tree only, and the full CI sequence passes clean: npm ci, npm run lint, npm test (84 passing), npm audit (found 0 vulnerabilities).
Some developer pages render without the app list section the parser expects — e.g. https://play.google.com/store/apps/dev?id=7502834977667077022 returns a valid page whose ds:3 blob carries no section at the mapped path. R.path() then returns undefined, and passing that into R.map() crashed with: TypeError: Cannot read properties of undefined (reading 'fantasy-land/map') at parseDeveloperApps (lib/developer.js:119) Guard the extraction: when the section is missing, resolve with an empty list instead of crashing. Healthy pages (string and numeric dev ids) are unaffected. Adds a regression test against the developer id reported in the issue. Fixes facundoolano#730
Author
|
Note: CI's |
Agi-Asi
force-pushed
the
fix/developer-no-apps-crash
branch
from
August 27, 2026 09:40
f2d8bc1 to
6466965
Compare
Owner
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
developer()crashes on some developer pages:Reproducible live with the developer id from #730:
The page (https://play.google.com/store/apps/dev?id=7502834977667077022) is a valid developer page ("Android Apps by Lategame Studio"), but its
ds:3blob carries no app list section at the mapped path — the store renders that content lazily.R.path()returnsundefined, and feeding that intoR.map()produces the ramda crash above.Fix
Guard the extraction: when the app list section is missing, resolve with an empty list instead of crashing. Healthy pages are unaffected (verified live with both the string id
Jam City, Inc.and the numeric id5700313618786177705).Testing
main, passes with this fix.npm test: 85 passing, 0 failingnpm run lint: cleanFixes #730