Audit of 0.8.4 found the repo's own gates green, so these came from manual
review; each is covered by a new regression test.
security/fetch.ts
- safeFetch re-attached Authorization/Cookie on a same-origin redirect that
followed a cross-origin hop (a -> b -> b), handing credentials to the second
host. Compare against the origin the caller trusted, not the previous hop.
- The private-network guard resolved the host, approved it, then let fetch
resolve again, so a low-TTL record could answer public for the check and
private for the connection. Pin the connection to the validated address,
preserving Host and TLS serverName. Opt out with pinDns: false.
- 0:0:0:0:0:ffff:127.0.0.1, ::ffff:7f00:1 and fec0::1 were not treated as
private. Add uncompressed IPv4-mapped forms, site-local IPv6, 198.18/15
and 192.0.0/24.
security/url.ts
- sanitizeUrl returned "//evil.com" verbatim via the relative-path fast path,
bypassing the host checks it had just run; in an href that navigates
cross-origin. Resolve protocol-relative input instead.
dev-server/gateway.ts
- Malformed base64 in an Authorization header threw out of checkAuth on an
unauthenticated path. Fail closed.
- split(":", 2) truncated passwords at the first colon, so a password
containing ":" could never authenticate.
- The credential compare short-circuited on length mismatch, leaking length
by timing. Extracted as verifyBasicAuth so it is testable.
authz/index.ts
- Namespace wildcards only matched the first segment, so "post:comment:*"
did not grant "post:comment:delete". Match at every depth.
uploader/operations.ts
- Validate transcoder dimensions and bitrate rather than trusting the declared
type, and reject ".." path segments.
package.json
- The brace-expansion override pinned 5.0.8, which is inside the advisory
range >=4.0.0 <5.0.9. Bump to 5.0.9; bun audit is now clean.
Verified: check:production passes (typecheck, lint, 1033 tests, format,
ASVS, public-API baseline, editor checks).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
WRNexusJS
WRNexusJS is a compiler-driven, SSR-first, Bun-native full-stack framework for building secure, fast, maintainable applications with .wrn pages, layouts, components, stores, server functions, client functions, typed outputs, APIs, validation, authentication, realtime rooms, and production tooling.
Current framework version: 0.8.0
Core principles
- Secure by default with CSP, CSRF, safe serialization, URL policies, request limits, SSRF protection, secret scanning, and release gates.
- Performance-first SSR with zero framework JavaScript for static pages and selective hydration for interactive pages.
- One compiler-understood
.wrnmodel for markup, props, state, outputs, and runtime-specific functions. - Backward-compatible package upgrades with migrations, generated references, validation scripts, and private publishing controls.
- Package kits that give developers public helpers, package tests, documentation, and complete UI blocks where a package has a developer-facing interface.
Quick start
bun install
bun run validate:0.8
bun run check
bun run dev
Create or upgrade a project:
bunx @wrnexus/cli@0.8.0 create my-app
bunx @wrnexus/cli@0.8.0 update --version=0.8.0 --report
Package kits in 0.8
All 39 framework packages expose a documented helper/API surface and package tests. UI-facing packages additionally own complete .wrn blocks composed from @wrnexus/ui:
@wrnexus/auth— complete account, sign-in, sign-up, MFA, passkey, recovery, device, provider, and security blocks.@wrnexus/captcha— challenge, field, status, extraction, verification, response, and context helpers.@wrnexus/i18n— recursive locale loading, fallback chains, request resolution, SSR/browser translations, language controls, and formatters.@wrnexus/image— responsive picture plans, secure loaders, placeholders, preload hints, audits, and image blocks.@wrnexus/realtime— typed messages, room connections, presence, typing, metadata, composer, status, and message blocks.@wrnexus/uploader— upload attributes, result validation, formatting, dropzone, and status blocks.@wrnexus/validation— parse/throw helpers, consistent error responses, summaries, and field errors.@wrnexus/ui— the complete shared design-system component catalog.
Infrastructure packages remain helper/API-only so database, encryption, security, compiler, server, and build packages do not pull browser UI into production server code.
Security note for encrypted HTTP bodies
@wrnexus/encryption supports authenticated application-layer request and response envelopes with method, path, request-ID, timestamp, expiry, key-rotation, body-size, and replay binding.
This feature does not replace HTTPS. It is appropriate for service-to-service calls, native/mobile clients, controlled agents, or selected fields with server-managed keys. It cannot hide data from an end user when a browser receives the decryption key.
Validation commands
bun run audit:packages
bun run test:package-kits
bun run validate:0.8
bun run security:framework
bun run sbom
bun run benchmark:framework
bun run validate:staging
bun run check