Skip to content

fix(deps): patch js-yaml and svgo advisories blocking Security Scanning #2089

Description

@cristim

The frontend lockfile on main at eac9a62 contains js-yaml 3.15.1 and 4.3.1 plus svgo 4.0.2. Running npm audit --audit-level=high reports two high-severity vulnerable packages and exits 1, blocking Security Scanning and CI Success. PR2071 run34415153948 reproduces this with a lockfile identical to main.

Current advisories:

Update frontend/package-lock.json within the existing parent ranges, including SVGO's required selector dependencies. Preserve package.json and the full-tree audit gate. Verify audit red before and green after, production frontend build, and Jest.

Related LeanerCloud/cloud-commitments-platform#79 covers earlier fast-uri/SVGO advisories; LeanerCloud/cloud-commitments-platform#165 covers the broader gating policy. Neither tracks these current advisory versions. All affected entries are dev dependencies; this report establishes CI failure and vulnerable installed versions, not production exploitability.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions