Skip to content

chore(security): bump js-yaml override to ^4.3.2 (GHSA-2883-xcg3-v3hh, alert #75) - #20

Merged
cdbartholomew merged 1 commit into
mainfrom
chore/security-daily-20260914-test-vectorize-connect-sdk-npm-root
Sep 23, 2026
Merged

cdbartholomew merged 1 commit into
mainfrom
chore/security-daily-20260914-test-vectorize-connect-sdk-npm-root

Conversation

@benfrank241

Copy link
Copy Markdown
Member

Daily security sweep — 2026-09-14. npm / root package-lock.json (the repo's only ecosystem/lockfile). One PR per (ecosystem, lockfile path).

Alert closed

alert advisory severity package scope vulnerable fixed in
#75 GHSA-2883-xcg3-v3hh high js-yaml dev >= 4.0.0, < 4.3.2 4.3.2

js-yaml's maxTotalMergeKeys limit does not bound CPU use for empty merge sources, so a crafted document can drive uncontrolled resource consumption through the merge-key path despite the cap.

The fix

The repo already carried a global overrides entry "js-yaml": "^4.3.1" from an earlier sweep. This moves it to ^4.3.2 and re-locks — resolved 4.3.1 → 4.3.2.

  • Transitive, not a direct dependency. The sole requester in the tree is @eslint/eslintrc, declaring ^4.1.1, which already accepts 4.3.2 — so a global override is correct here and no parent scoping is needed.
  • Patch bump on the v4-legacy line. js-yaml's latest dist-tag is 5.4.2; that is a major, is not required to clear the advisory, and would be a "propose, don't auto-apply" change. Staying on ^4.3.2.
  • Regenerated with npm install --package-lock-only (no --force, no --legacy-peer-deps). Diff is 4 insertions / 4 deletions across 2 files — the one overrides line plus js-yaml's version/resolved/integrity. No other package moved.
  • npm audit after the change no longer reports js-yaml; the two advisories it still reports are postcss-selector-parser and @humanfs/node, already covered by the open PRs below.

Verification

This repo's only CI workflow is the GitLeaks secret scan (secret-scan.yml) — there is no build/test/lint gate in CI. Locally, package.json has dev/build/start/lint and no test script, and next build is already red on main from pre-existing @typescript-eslint/no-explicit-any errors in source (tracked in #17, unrelated to dependencies). So this was verified three ways against a pristine origin/main control worktree at the same commit (d6f92b2):

  1. Differential. npm ci exit 0 both sides. npm run build exits 1 on both sides with identical normalized diagnostic sets — 12 signature lines each (6 file paths + 6 diagnostics), diff empty. No new failure introduced.
  2. True green. Rebuilt both sides with a temporary, uncommitted next.config.ts carrying eslint: { ignoreDuringBuilds: true }, bypassing only the unrelated pre-existing lint gate. Both sides exit 0, and the emitted route table is byte-identical (18 lines). The temporary edit was reverted before committing and git status confirmed clean — it is not in this diff.
  3. Package-specific artifact check. js-yaml is loaded by @eslint/eslintrc, which this repo instantiates directly (eslint.config.mjs uses FlatCompat). Identical ESLint diagnostics across the version change is the meaningful behavioural signal for this package — the analogue of byte-comparing emitted CSS for a PostCSS bump.

Not included

No alerts were dismissed. No backlog items — nothing failed that is attributable to this change.

Note for whoever merges

PRs #18, #19 and this one all touch the same overrides block and the same package-lock.json, and are deliberately not stacked — each is branched from main so each gets its own CI. Whichever merges after the first will need a rebase and a re-lock so all three fixes survive.

Not merging — opened for review.

… alert #75)

js-yaml < 4.3.2 does not limit CPU use for empty merge sources, so
maxTotalMergeKeys does not bound the work done when parsing a crafted
document (uncontrolled resource consumption).

Transitive, dev scope. Sole parent is @eslint/eslintrc (requests ^4.1.1,
which already accepts 4.3.2), so the existing global override just moves
^4.3.1 -> ^4.3.2. Resolved 4.3.1 -> 4.3.2 (patch on the v4-legacy line;
the 5.x latest tag is a major and unnecessary here).

Closes #75
@benfrank241 benfrank241 added dependencies Pull requests that update a dependency file security labels Sep 14, 2026
@cdbartholomew cdbartholomew added the p1 Priority: high label Sep 23, 2026
@cdbartholomew cdbartholomew self-assigned this Sep 23, 2026
@cdbartholomew
cdbartholomew merged commit a51cbfd into main Sep 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file p1 Priority: high security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants