Known advisories in a clean install
npm audit on a fresh install of all three published packages (0.6.0,
measured 2026-09-30) reports eight packages: four high, four moderate.
Installing @wasit-dev/cli alone reports seven (four high, three moderate),
since it pulls a smaller slice of the same graph. None originate in Wasit's own
code or declared dependencies. All of them trace to @stellar/mpp@0.7.1, which
brings older copies of two packages alongside the ones Wasit declares:
@stellar/stellar-sdk@15.1.0, because@stellar/mpppeers on^15.1.0while this project declares^16.1.0. That copy bringsaxios@1.15.0andtoml@3.0.0(high). The SDK Wasit itself declares resolvesaxios@1.18.0, which no current advisory matches.mppx@0.6.31, because@stellar/mpppeers on^0.6.29. The "gas draining" advisories (moderate) affectmppxbefore 0.8.1; themppxWasit declares resolves 0.8.19.
The three @wasit-dev/* packages appear in that count only because npm marks
a package that depends on an affected one; there is no advisory against Wasit.
There is no downstream fix — the only lever is those two peer ranges, which we
do not control. They are reported upstream as
stellar-mpp-sdk#70 and
written up in findings/upstream-sdk.md; the
fix has merged upstream, but @stellar/mpp@0.7.1 is still the latest on npm
(checked 2026-09-30).
npm run verify:clean-install installs all three packages and prints the
audit on every CI run, so the count is measured rather than remembered.
This is stated here rather than left to be discovered: a tool that checks other people's compliance should be legible about its own supply chain.