chore(security): bump js-yaml override to ^4.3.2 (GHSA-2883-xcg3-v3hh, alert #75) - #20
Merged
cdbartholomew merged 1 commit intoSep 23, 2026
Conversation
… alert #75) js-yaml < 4.3.2 does not limit CPU use for empty merge sources, so maxTotalMergeKeys does not bound the work done when parsing a crafted document (uncontrolled resource consumption). Transitive, dev scope. Sole parent is @eslint/eslintrc (requests ^4.1.1, which already accepts 4.3.2), so the existing global override just moves ^4.3.1 -> ^4.3.2. Resolved 4.3.1 -> 4.3.2 (patch on the v4-legacy line; the 5.x latest tag is a major and unnecessary here). Closes #75
cdbartholomew
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Daily security sweep — 2026-09-14. npm / root
package-lock.json(the repo's only ecosystem/lockfile). One PR per (ecosystem, lockfile path).Alert closed
GHSA-2883-xcg3-v3hhjs-yaml>= 4.0.0, < 4.3.24.3.2js-yaml'smaxTotalMergeKeyslimit does not bound CPU use for empty merge sources, so a crafted document can drive uncontrolled resource consumption through the merge-key path despite the cap.The fix
The repo already carried a global
overridesentry"js-yaml": "^4.3.1"from an earlier sweep. This moves it to^4.3.2and re-locks — resolved4.3.1→4.3.2.@eslint/eslintrc, declaring^4.1.1, which already accepts4.3.2— so a global override is correct here and no parent scoping is needed.v4-legacyline.js-yaml'slatestdist-tag is5.4.2; that is a major, is not required to clear the advisory, and would be a "propose, don't auto-apply" change. Staying on^4.3.2.npm install --package-lock-only(no--force, no--legacy-peer-deps). Diff is 4 insertions / 4 deletions across 2 files — the oneoverridesline plusjs-yaml'sversion/resolved/integrity. No other package moved.npm auditafter the change no longer reportsjs-yaml; the two advisories it still reports arepostcss-selector-parserand@humanfs/node, already covered by the open PRs below.Verification
This repo's only CI workflow is the GitLeaks secret scan (
secret-scan.yml) — there is no build/test/lint gate in CI. Locally,package.jsonhasdev/build/start/lintand notestscript, andnext buildis already red onmainfrom pre-existing@typescript-eslint/no-explicit-anyerrors in source (tracked in #17, unrelated to dependencies). So this was verified three ways against a pristineorigin/maincontrol worktree at the same commit (d6f92b2):npm ciexit 0 both sides.npm run buildexits 1 on both sides with identical normalized diagnostic sets — 12 signature lines each (6 file paths + 6 diagnostics),diffempty. No new failure introduced.next.config.tscarryingeslint: { ignoreDuringBuilds: true }, bypassing only the unrelated pre-existing lint gate. Both sides exit 0, and the emitted route table is byte-identical (18 lines). The temporary edit was reverted before committing andgit statusconfirmed clean — it is not in this diff.js-yamlis loaded by@eslint/eslintrc, which this repo instantiates directly (eslint.config.mjsusesFlatCompat). Identical ESLint diagnostics across the version change is the meaningful behavioural signal for this package — the analogue of byte-comparing emitted CSS for a PostCSS bump.Not included
GHSA-w9m9-85wc-3x92(postcss-selector-parser) — already covered by open PR chore(security): bump postcss-selector-parser >=6.1.3 (GHSA-w9m9-85wc-3x92, alert #73) #18.GHSA-p498-v437-472g(@humanfs/node) — already covered by open PR chore(security): bump @humanfs/node to ^0.16.8 (GHSA-p498-v437-472g, alert #74) #19.No alerts were dismissed. No backlog items — nothing failed that is attributable to this change.
Note for whoever merges
PRs #18, #19 and this one all touch the same
overridesblock and the samepackage-lock.json, and are deliberately not stacked — each is branched frommainso each gets its own CI. Whichever merges after the first will need a rebase and a re-lock so all three fixes survive.Not merging — opened for review.