- node-whois was declared in package.json but required/imported nowhere in the codebase (verified via repo-wide grep) -- pure dead weight that was dragging in a critical arbitrary-code-execution chain (underscore 1.5.2 via optimist, CVSS 9.8). No fixed version exists upstream (latest 2.1.3 still depends on the same vulnerable optimist/underscore), so the only real fix was removal. Zero behavior change since nothing called it. - node-cron 3.0.3 -> 4.6.0: only real usage is two plain cron.schedule() calls in src/features/hijack-alerts/retry-scheduler.ts and src/features/aspa-adoption/scheduler.ts -- API unchanged, low risk. 4.6.0 has zero runtime deps (drops the vulnerable uuid transitive dep) and ships its own TS types, so @types/node-cron was also removed to avoid duplicate/conflicting type declarations. - repository/bugs URLs in package.json corrected from the GitHub repo (deleted 2026-07-14) to the actual Gitea repo. 12 -> 6 vulnerabilities (6 critical/1 high/5 moderate -> 2 critical/1 high/3 moderate). Remaining 6 are entirely in the vitest/vite/esbuild dev-tooling chain (vite dev-server SSRF, GHSA-67mh-4wv8-2f99) -- not production-exposed, and fixing requires a vitest 2.x -> 4.x major bump that needs its own test-suite verification pass, not folded into this commit. tsc --noEmit confirms no new type errors from the node-cron/types change (remaining TS6133 unused-var warnings in src/sources/*.ts are pre-existing skeleton-source stubs, unrelated to this commit).
96 lines
2.4 KiB
JSON
96 lines
2.4 KiB
JSON
{
|
|
"name": "peercortex",
|
|
"version": "0.7.0",
|
|
"description": "AI-Powered Network Intelligence Platform — MCP Server for PeeringDB, RIPE Stat, BGP analysis, RPKI monitoring, and peering automation. Powered by local Ollama.",
|
|
"main": "dist/mcp-server/index.js",
|
|
"types": "dist/mcp-server/index.d.ts",
|
|
"bin": {
|
|
"peercortex": "dist/mcp-server/index.js"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc",
|
|
"dev": "tsx watch src/mcp-server/index.ts",
|
|
"start": "node dist/mcp-server/index.js",
|
|
"lint": "eslint src/",
|
|
"lint:fix": "eslint src/ --fix",
|
|
"typecheck": "tsc --noEmit",
|
|
"test": "vitest run",
|
|
"test:watch": "vitest",
|
|
"test:coverage": "vitest run --coverage",
|
|
"clean": "rm -rf dist/",
|
|
"prepublishOnly": "npm run build"
|
|
},
|
|
"keywords": [
|
|
"mcp",
|
|
"mcp-server",
|
|
"peeringdb",
|
|
"bgp",
|
|
"rpki",
|
|
"ripe-stat",
|
|
"network-intelligence",
|
|
"peering",
|
|
"asn-lookup",
|
|
"prefix-lookup",
|
|
"internet-exchange",
|
|
"route-leak-detection",
|
|
"bgp-hijack-detection",
|
|
"bgp-monitoring",
|
|
"bgp-analysis",
|
|
"peering-automation",
|
|
"rpki-monitoring",
|
|
"rpki-compliance",
|
|
"noc-tools",
|
|
"network-operator",
|
|
"ollama",
|
|
"self-hosted",
|
|
"local-ai",
|
|
"claude-code",
|
|
"irr-query",
|
|
"route-views",
|
|
"bgp-anomaly"
|
|
],
|
|
"author": "Rene Fichtmueller",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://gitea.context-x.org/rene/PeerCortex.git"
|
|
},
|
|
"bugs": {
|
|
"url": "https://gitea.context-x.org/rene/PeerCortex/issues"
|
|
},
|
|
"homepage": "https://peercortex.org",
|
|
"engines": {
|
|
"node": ">=20.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@grpc/grpc-js": "^1.14.3",
|
|
"@grpc/proto-loader": "^0.8.0",
|
|
"@modelcontextprotocol/sdk": "^1.12.0",
|
|
"axios": "^1.6.0",
|
|
"better-sqlite3": "^11.7.0",
|
|
"cheerio": "^1.0.0",
|
|
"fastify": "^5.8.5",
|
|
"joi": "^17.11.0",
|
|
"node-cron": "^4.6.0",
|
|
"ollama": "^0.5.12",
|
|
"pg": "^8.11.0",
|
|
"playwright": "^1.40.0",
|
|
"puppeteer": "^24.42.0",
|
|
"zod": "^3.24.0"
|
|
},
|
|
"devDependencies": {
|
|
"@playwright/test": "^1.40.0",
|
|
"@types/better-sqlite3": "^7.6.12",
|
|
"@types/node": "^22.10.0",
|
|
"@types/pg": "^8.11.0",
|
|
"@typescript-eslint/eslint-plugin": "^8.18.0",
|
|
"@typescript-eslint/parser": "^8.18.0",
|
|
"@vitest/coverage-v8": "^2.1.0",
|
|
"eslint": "^9.16.0",
|
|
"nock": "^13.4.0",
|
|
"tsx": "^4.19.0",
|
|
"typescript": "^5.7.0",
|
|
"vitest": "^2.1.0"
|
|
}
|
|
}
|