From 4d6e49f4d2ac8a29cddb4dc3021f932307764c1e Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Sat, 25 Jul 2026 23:45:26 -0400 Subject: [PATCH] fix(#2654): bump js-yaml past the merge-key DoS advisory (#2655) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * fix(#2654): bump js-yaml past the merge-key DoS advisory js-yaml was pinned ^4.2.0, inside the vulnerable 4.0.0 - 4.2.0 range of GHSA-52cp-r559-cp3m (YAML merge-key chains force quadratic CPU, CVSS 7.5). Bump to ^4.2.1; the lockfile resolves 4.3.0. It is a devDependency with no reachability from shipped runtime code under gsd-core/bin/ or src/ — the consumers are scripts/workflow-policy.cjs and five test files. The path worth closing is CI: workflow-policy parses workflow frontmatter during the Tests workflow, and on a fork PR that frontmatter is attacker-controlled. Scoped to js-yaml only. The remaining brace-expansion advisory is not fixed by this and is deliberately left alone: npm audit fix takes the high count from 1 to 5, because the three copies nested under eslint land on 1.1.16, which still compares inside the advisory's <=5.0.7 range. Closing it needs an eslint major or an overrides entry. Co-Authored-By: Claude Opus 5 * chore(#2654): backfill changeset pr number to 2655 --------- Co-authored-by: Claude Opus 5 --- .changeset/lively-finches-forage.md | 5 +++++ package-lock.json | 8 ++++---- package.json | 2 +- 3 files changed, 10 insertions(+), 5 deletions(-) create mode 100644 .changeset/lively-finches-forage.md diff --git a/.changeset/lively-finches-forage.md b/.changeset/lively-finches-forage.md new file mode 100644 index 000000000..10b0eb46d --- /dev/null +++ b/.changeset/lively-finches-forage.md @@ -0,0 +1,5 @@ +--- +type: Security +pr: 2655 +--- +**Dev-tooling `js-yaml` bumped past the merge-key DoS advisory** — `js-yaml` was pinned `^4.2.0`, inside the vulnerable `4.0.0 - 4.2.0` range of GHSA-52cp-r559-cp3m (quadratic CPU on YAML merge-key chains). It is a devDependency with no shipped-runtime reachability, but `scripts/workflow-policy.cjs` parses workflow frontmatter in CI, which is attacker-controlled on a fork PR. Now `^4.2.1`. (#2654) diff --git a/package-lock.json b/package-lock.json index ef0a5ccfb..230d9d369 100644 --- a/package-lock.json +++ b/package-lock.json @@ -28,7 +28,7 @@ "eslint-plugin-no-only-tests": "^3.4.0", "fast-check": "^4.8.0", "globals": "^16.5.0", - "js-yaml": "^4.2.0", + "js-yaml": "^4.2.1", "typescript": "^6.0.3", "typescript-eslint": "^8.60.0" }, @@ -3842,9 +3842,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.2.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz", - "integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==", + "version": "4.3.0", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz", + "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==", "dev": true, "funding": [ { diff --git a/package.json b/package.json index 1000550c3..9c4d1dcfe 100644 --- a/package.json +++ b/package.json @@ -65,7 +65,7 @@ "eslint-plugin-no-only-tests": "^3.4.0", "fast-check": "^4.8.0", "globals": "^16.5.0", - "js-yaml": "^4.2.0", + "js-yaml": "^4.2.1", "typescript": "^6.0.3", "typescript-eslint": "^8.60.0" },