Skip to content

chore(security): bump js-yaml to 4.3.2 in datasheetsChat (closes #81) - #13

Merged
cdbartholomew merged 1 commit into
mainfrom
chore/security-daily-20260914-rag-101-workshop-npm-datasheetschat
Sep 25, 2026
Merged

cdbartholomew merged 1 commit into
mainfrom
chore/security-daily-20260914-rag-101-workshop-npm-datasheetschat

Conversation

@benfrank241

Copy link
Copy Markdown
Member

Recreates the Dependabot fix for the remaining fixable alert on datasheetsChat/package-lock.json on a human-authored branch so it gets CI.

Closes

Alert Package Severity Advisory Change
#81 js-yaml high GHSA-2883-xcg3-v3hh 4.3.1 → 4.3.2

What changed

The root overrides entry "js-yaml": "^4.3.1" was already floor-pinning this package, so the fix is a one-character floor bump to "^4.3.2" plus a re-lock. The caret keeps resolution on the 4.x line (4.3.2 is the current 4.x tip; 5.x is a major bump and remains a maintainer decision). The sole consumer, @eslint/eslintrc, declares js-yaml: ^4.1.1, so 4.3.2 is in-range for the parent — the override is not forcing anything the tree would reject.

Diff is 4 lines across 2 files: the override line plus the single js-yaml lockfile entry. No native-package churn.

Regenerated with npm install --package-lock-only --ignore-scripts. No --force, no --legacy-peer-deps.

Verification (differential, against a pristine main control worktree)

This repo's only CI workflow is secret-scan.yml, and main is already red on npm run build, so both gates were run on the branch and on an untouched main checkout at the same commit and the outputs compared.

Gate main (control) This branch Verdict
npm ci exit 0 exit 0 pass
npm run build fails — src/app/api/chat/route.ts:134 LanguageModelV1 not assignable to LanguageModel fails identically pre-existing, byte-identical output, no regression
npm run lint unrunnable — next lint finds no ESLint config and drops into an interactive prompt identical pre-existing, no regression
npm run test no test script in package.json — skipped

Build logs from the two trees are byte-identical after normalising the compile-timing string.

Because js-yaml is a dev-scope dependency that the build does not exercise, the upgraded package was also smoke-tested directly: load of a nested mapping/sequence, a dump→load round-trip that compares JSON-identical, and confirmation that the !!js/function tag is still rejected.

Interaction with the other open PRs on this lockfile

PRs #11 (postcss-selector-parser) and #12 (@humanfs/node) are open against the same datasheetsChat/package-lock.json. Merge-compatibility was tested rather than assumed — this branch was test-merged against both heads, individually and together:

In every order the merged lockfile keeps all three fixes (js-yaml 4.3.2, postcss-selector-parser 6.1.4, @humanfs/node 0.16.8). No rebase or re-lock is required for any merge order — the three edits land in disjoint regions of the lockfile.

That said, this is now the third open PR against this one lockfile, and none of the three have been merged. Flagging the pile-up.

Not included

Alert #80 (@ai-sdk/provider-utils, GHSA-866g-f22w-33x8, low) is deliberately not bundled here, and its status has changed in a way worth reading — see the note appended to #10.

Closes Dependabot alert #81 (GHSA-2883-xcg3-v3hh, high).
js-yaml 4.3.1 -> 4.3.2 via the existing root overrides entry.
@benfrank241 benfrank241 added dependencies Pull requests that update a dependency file security labels Sep 14, 2026
@cdbartholomew cdbartholomew added the p1 Priority: high label Sep 23, 2026
@cdbartholomew cdbartholomew self-assigned this Sep 23, 2026
@cdbartholomew
cdbartholomew merged commit 6146882 into main Sep 25, 2026
1 check passed
@cdbartholomew
cdbartholomew deleted the chore/security-daily-20260914-rag-101-workshop-npm-datasheetschat branch September 25, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file p1 Priority: high security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants