Problem: npm audit --omit=dev (2026-09-07, weekly maintenance routine) reports a critical severity finding — "Arbitrary code execution in protobufjs" plus several other protobufjs advisories (prototype pollution / code-injection gadgets in generated message constructors, DoS via unbounded recursion) — reachable through onnx-proto → onnxruntime-web → @ricky0123/vad-web, a direct production dependency (package.json dependencies).
Scope: @ricky0123/vad-web (pinned ^0.0.24, installed 0.0.24) and onnxruntime-web (pinned exact 1.14.0) are imported directly in the shipped extension bundle — confirmed usage in src/vad/OnscreenVADClient.ts, src/vad/VADConfigs.ts, src/offscreen/vad_handler.ts, and src/offscreen/synthetic-audio.ts (the offscreen-document VAD pipeline described in src/vad/README.md). This is genuine shipped-product exposure, not dev-only tooling. Out of scope: the other npm audit findings rooted in Node-side dev tooling only (express/http-proxy-middleware/serve-handler, used by server.js / npm start, not bundled into the extension) — lower priority, not filed here.
Reproduction / verification:
npm ci && npm audit --omit=dev --json
- Observe
protobufjs at severity: "critical" with fixAvailable: {"name":"@ricky0123/vad-web","version":"0.0.30","isSemVerMajor":true} — the only available fix is a @ricky0123/vad-web bump (0.0.24 → 0.0.30), which pulls a newer onnxruntime-web/onnx-proto/protobufjs.
- Also present in the same chain:
onnx-proto (high) and onnxruntime-web (high), both fixed only by the same bump.
Expected: no critical/high vulnerabilities in the dependency chain that ships inside the browser-extension bundle. Actual: 1 critical + 2 high findings, all rooted in protobufjs, all requiring the same @ricky0123/vad-web major-boundary bump to resolve.
Acceptance criteria:
@ricky0123/vad-web (and its transitive onnxruntime-web/onnx-proto/protobufjs) upgraded past the vulnerable versions, verified by a clean npm audit --omit=dev for this chain.
- Full VAD regression coverage passes post-bump:
npm test, the VAD unit/contract tests, and the VAD benchmark (npm run bench:vad) — per src/vad/README.md's note that all 4 copied WASM files are load-bearing, confirm npm run copy-onnx still produces the expected WASM set against the new onnxruntime-web version (file names/count can change across versions).
- A real-host or Layer-3/4 smoke pass confirms the offscreen VAD pipeline (
src/offscreen/vad_handler.ts) still detects speech correctly after the bump, since this is exactly the kind of "looks-mechanical-is-a-trap" dependency swap doc/codebase-caution-map.md warns about.
Notes/Hypotheses (non-binding): fixAvailable.isSemVerMajor: true is likely an artifact of @ricky0123/vad-web being pre-1.0 (npm treats any 0.0.x → 0.0.y bump as a major-equivalent boundary) rather than evidence of an actual breaking API change — worth checking the vad-web changelog/diff between 0.0.24 and 0.0.30 before assuming a large migration. Per AGENTS.md, this routine does not bump dependencies itself; filing for a human/agent session to pick up via the normal fail-first-TDD + isolated-worktree flow.
Problem:
npm audit --omit=dev(2026-09-07, weekly maintenance routine) reports a critical severity finding — "Arbitrary code execution in protobufjs" plus several other protobufjs advisories (prototype pollution / code-injection gadgets in generated message constructors, DoS via unbounded recursion) — reachable throughonnx-proto→onnxruntime-web→@ricky0123/vad-web, a direct production dependency (package.jsondependencies).Scope:
@ricky0123/vad-web(pinned^0.0.24, installed0.0.24) andonnxruntime-web(pinned exact1.14.0) are imported directly in the shipped extension bundle — confirmed usage insrc/vad/OnscreenVADClient.ts,src/vad/VADConfigs.ts,src/offscreen/vad_handler.ts, andsrc/offscreen/synthetic-audio.ts(the offscreen-document VAD pipeline described insrc/vad/README.md). This is genuine shipped-product exposure, not dev-only tooling. Out of scope: the othernpm auditfindings rooted in Node-side dev tooling only (express/http-proxy-middleware/serve-handler, used byserver.js/npm start, not bundled into the extension) — lower priority, not filed here.Reproduction / verification:
npm ci && npm audit --omit=dev --jsonprotobufjsatseverity: "critical"withfixAvailable: {"name":"@ricky0123/vad-web","version":"0.0.30","isSemVerMajor":true}— the only available fix is a@ricky0123/vad-webbump (0.0.24 → 0.0.30), which pulls a neweronnxruntime-web/onnx-proto/protobufjs.onnx-proto(high) andonnxruntime-web(high), both fixed only by the same bump.Expected: no critical/high vulnerabilities in the dependency chain that ships inside the browser-extension bundle. Actual: 1 critical + 2 high findings, all rooted in
protobufjs, all requiring the same@ricky0123/vad-webmajor-boundary bump to resolve.Acceptance criteria:
@ricky0123/vad-web(and its transitiveonnxruntime-web/onnx-proto/protobufjs) upgraded past the vulnerable versions, verified by a cleannpm audit --omit=devfor this chain.npm test, the VAD unit/contract tests, and the VAD benchmark (npm run bench:vad) — persrc/vad/README.md's note that all 4 copied WASM files are load-bearing, confirmnpm run copy-onnxstill produces the expected WASM set against the newonnxruntime-webversion (file names/count can change across versions).src/offscreen/vad_handler.ts) still detects speech correctly after the bump, since this is exactly the kind of "looks-mechanical-is-a-trap" dependency swapdoc/codebase-caution-map.mdwarns about.Notes/Hypotheses (non-binding):
fixAvailable.isSemVerMajor: trueis likely an artifact of@ricky0123/vad-webbeing pre-1.0 (npm treats any0.0.x→0.0.ybump as a major-equivalent boundary) rather than evidence of an actual breaking API change — worth checking the vad-web changelog/diff between 0.0.24 and 0.0.30 before assuming a large migration. PerAGENTS.md, this routine does not bump dependencies itself; filing for a human/agent session to pick up via the normal fail-first-TDD + isolated-worktree flow.