Repository navigation
fix(deps): bump brace-expansion, fast-xml-parser, js-yaml, browserslist, fast-uri to patch disclosed CVEs - #693
Open
Svector-anu wants to merge 1 commit into
Conversation
…st, fast-uri to patch disclosed CVEs Advisories: - brace-expansion 1.1.14 -> 1.1.18: GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 (ReDoS/OOM DoS, HIGH) - fast-xml-parser 5.9.3 -> 5.10.1: GHSA-8r6m-32jq-jx6q (HIGH) - js-yaml 3.14.2 -> 3.15.1: GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj (HIGH), GHSA-h67p-54hq-rp68 (MODERATE) - browserslist 4.28.4 -> 4.28.7: GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx (HIGH) - fast-uri 3.1.2 -> 3.1.6: GHSA-4c8g-83qw-93j6, GHSA-7p8r-x3mc-p8w7, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp, GHSA-v2hh-gcrm-f6hx (HIGH) Pinned via package.json overrides + regenerated package-lock.json (npm install --package-lock-only). All fixes stay within the currently resolved major version, so no code changes are required.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated dependency bump addressing five disclosed CVE groups in transitive npm dependencies. All fixes stay within the currently-resolved major version line, so no source changes are required — only
package.json(newoverridesblock) and the regeneratedpackage-lock.json.brace-expansion(prod, transitive)fast-xml-parser(prod, transitive)js-yaml(dev, transitive)browserslist(dev, transitive)fast-uri(dev, transitive)None of these packages are declared directly in
package.json's owndependencies/devDependencies(they're pulled in transitively), so the fix uses anoverridesblock to pin each to its lowest same-major patched version, then regenerates the lockfile withnpm install --package-lock-only.Verification
osv-scanner scan source --recursive --no-ignore --format=json .(before and after)osv-scannerreports zero findings for these 5 packages; onlyundici@5.29.0(11 findings, needs a major-version bump — same "requires a malicious server" risk-acceptance rationale your team already applied toGHSA-g9mf-h72j-4rw9inosv-scanner.toml) anduuid@3.4.0/8.3.2(1 moderate finding each, fix requires a major-version bump past the pinned^8.3.2range) remain, left out of scope here as breaking-change bumpsaction.ymltargetsnode24)Detected by osv-scanner. No code changes outside
package.json/package-lock.json.Note: this repo already has three open Dependabot PRs (#557, #610, #633) targeting older, now-superseded versions of
brace-expansion,js-yaml, andfast-xml-parserthat predate these CVE disclosures and would not fix them even if merged as-is; this PR supersedes those three for the packages it touches.