Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

pastelsky/bundlephobia
bundlephobia @ fb9c658
3
Fixes
0
CVEs
MEDIUM
Peak severity
100.0%
Coverage
Highlights
Denial of Service: 1 prior fix. Scrutinize any change in this area.
operations/haproxy/haproxy.cfg: most-fixed (2 issues). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Spoofing: The CF-Connecting-IP header was accepted without proper IP validation, allowing attackers to forge client IP addresses and bypass IP-based controls.
Denial of Service: Build operations lacked duration limits, enabling resource exhaustion via long-running or queued requests.
Reflected XSS: Using dangerouslySetInnerHTML with DOMPurify to render package descriptions allowed reflected XSS; native JSX escaping was adopted instead.