Run the following from the named directory before a release:
no.tiwas.booleantoolbox:npm audit --omit=dev --audit-level=highapps/dashboard:npm audit --audit-level=highandnpm audit --omit=dev --audit-level=high
The dashboard's development and production dependency trees must have no high-or-higher findings. The Homey runtime must have no high-or-higher findings; its remaining moderate findings are recorded below.
homey-api 3.20.0 still uses Socket.IO 2.x, which still pulls in parseuri 0.0.6. Its ReDoS advisory has no compatible fixed transitive version: parseuri 3.x is not API-compatible with the Socket.IO 2.x client. homey-api 3.20.0 declares Node.js 22 or newer, which matches the Homey Pro (Early 2023) runtime; its code uses no API newer than Node.js 16.
The app is a Socket.IO client; it does not expose a listening Socket.IO endpoint. The remaining risk therefore requires a malicious or compromised Homey/API endpoint to supply a crafted URI. This moderate upstream risk is accepted only while all of the following remain true:
- the app uses the authenticated Homey API endpoint rather than an untrusted URL;
socket.io-parseris pinned throughoverridesto 3.3.6 or later, which fixes GHSA-2m8v-j782-fhvr;npm audit --omit=dev --audit-level=highremains clean; and- the dependency is reviewed when Homey supports the Node.js version required by a fixed
homey-apirelease, or when Socket.IO 2.x receives a compatible fix.
Do not use npm audit fix --force for the Homey app: its suggested homey-api change is not a compatible upgrade path.