Repository navigation
Conversation
CI runs 'npm audit' as a required step, and the current lockfile fails it with 6 vulnerabilities (3 high, 2 moderate, 1 low), all in dev-tool transitive dependencies: - serialize-javascript <=7.0.4 (high, RCE + DoS advisories) via mocha - diff 5.0.0-5.2.1 (jsdiff DoS in parsePatch/applyPatch) via mocha - js-yaml 4.0.0-4.3.0 (quadratic-CPU DoS advisories) via eslint/mocha - brace-expansion (DoS family) via minimatch consumers - ajv <6.14.0 (ReDoS) via eslint None are fixable by 'npm audit fix' alone: even mocha@latest still pins vulnerable serialize-javascript/diff ranges. Add npm 'overrides' pinning each package to its patched line and regenerate the lockfile. Runtime dependencies are untouched — the diff is dev-tree only, and the full CI sequence passes clean: npm ci, npm run lint, npm test (84 passing), npm audit (found 0 vulnerabilities).
Author
|
Note: CI's |
Agi-Asi
force-pushed
the
fix/categories-empty-list
branch
from
August 27, 2026 09:40
d07b78c to
f2cccef
Compare
… id list Google Play no longer renders the category navigation menu in the static HTML of /store/apps (it is lazy-loaded client side), so the cheerio scrape of 'ul li a' hrefs found nothing and categories() silently degraded to just ['APPLICATION'] — verified live: the store page markup contains zero matching anchors. Serve the category ids from constants.category instead. That list is already the source of truth this library maintains for list() validation, and every id maps to a live /store/apps/category/<ID> page (spot-checked APPLICATION, GAME, GAME_ACTION, ART_AND_DESIGN, WATCH_FACE, ANDROID_WEAR, FAMILY against the live store). The function keeps its async signature and keeps accepting (and ignoring) options, so existing callers are unaffected — they just get the full list back instead of one entry. The existing test 'should have all categories from constant list of categories' (categories ⊆ constants.category) is now exactly satisfied; the first test gains a regression guard against the single-entry degradation. Fixes facundoolano#671
Agi-Asi
force-pushed
the
fix/categories-empty-list
branch
from
August 27, 2026 09:42
f2cccef to
cab05a0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
categories()returns just['APPLICATION'](#671). Google Play no longer renders the category navigation menu in the static HTML of/store/apps— it is lazy-loaded client side — so the cheerio scrape oful li ahrefs finds nothing and only the hardcodedAPPLICATIONentry survives. Verified live: the store page markup contains zero matching anchors today ($('ul li a')→ 0 elements).Fix
Serve the category ids from
constants.categoryinstead of scraping. That list is already the source of truth this library maintains (it's whatlist()accepts), and every id maps to a live/store/apps/category/<ID>page — spot-checkedAPPLICATION,GAME,GAME_ACTION,ART_AND_DESIGN,WATCH_FACE,ANDROID_WEAR,FAMILYagainst the live store, all 200s.The function keeps its promise-returning signature and keeps accepting (and ignoring) its options argument, so existing callers are unaffected — they just get the full 54-entry list back instead of one entry.
Notably, the existing test
should have all categories from constant list of categoriesasserts exactlycategories() ⊆ constants.category, which this implementation satisfies by construction.Testing
length > 1, includesAPPLICATIONandGAME).npm test: 84 passing, 0 failing;npm run lint: cleanFixes #671