* fix(#2654): bump js-yaml past the merge-key DoS advisory js-yaml was pinned ^4.2.0, inside the vulnerable 4.0.0 - 4.2.0 range of GHSA-52cp-r559-cp3m (YAML merge-key chains force quadratic CPU, CVSS 7.5). Bump to ^4.2.1; the lockfile resolves 4.3.0. It is a devDependency with no reachability from shipped runtime code under gsd-core/bin/ or src/ — the consumers are scripts/workflow-policy.cjs and five test files. The path worth closing is CI: workflow-policy parses workflow frontmatter during the Tests workflow, and on a fork PR that frontmatter is attacker-controlled. Scoped to js-yaml only. The remaining brace-expansion advisory is not fixed by this and is deliberately left alone: npm audit fix takes the high count from 1 to 5, because the three copies nested under eslint land on 1.1.16, which still compares inside the advisory's <=5.0.7 range. Closing it needs an eslint major or an overrides entry. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * chore(#2654): backfill changeset pr number to 2655 --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
435 B
435 B
type, pr
| type | pr |
|---|---|
| Security | 2655 |
Dev-tooling js-yaml bumped past the merge-key DoS advisory — js-yaml was pinned ^4.2.0, inside the vulnerable 4.0.0 - 4.2.0 range of GHSA-52cp-r559-cp3m (quadratic CPU on YAML merge-key chains). It is a devDependency with no shipped-runtime reachability, but scripts/workflow-policy.cjs parses workflow frontmatter in CI, which is attacker-controlled on a fork PR. Now ^4.2.1. (#2654)