Skip to content

Commit 73a7a55

Browse files
Regenerate CVE appendix for 606984e
1 parent 606984e commit 73a7a55

1 file changed

Lines changed: 8 additions & 4 deletions

File tree

docs/security-audit-cve-appendix.md

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,15 @@
2626
2727
| Field | Value |
2828
|---|---|
29-
| Release | `lockfile-commit` = `61ebf2a47d41806f39602528e8476cb433dcde5c` |
29+
| Release | `lockfile-commit` = `606984e369c4a7da6a06ebfb4c3be0d1ea379060` |
3030
| Lockfile | `pnpm-lock.yaml` |
31-
| Lockfile sha256 | `a6fa36d1a57d793a5d315f963a365a769422cc5bc842a49228cf5bcb53a84de1` |
31+
| Lockfile sha256 | `e4020c1e9dc4218cadac9dae2b5caacccf4e8eefc40939cb8918e0ac15ea4365` |
3232
| Generator | `scripts/regen-cve-appendix.mjs` (parser `scripts/lib/pnpm-audit-parser.mjs`) |
3333
| pnpm major (pinned) | `10` |
34-
| Total advisories | 0 (0 critical / 0 high / 0 moderate / 0 low / 0 info) |
34+
| Total advisories | 3 (0 critical / 0 high / 2 moderate / 1 low / 0 info) |
3535

36-
_No advisories surfaced by `pnpm audit --json --audit-level=info` against this lockfile._
36+
| Severity | ID | Package | Version | Dep path | Title | Audit ledger |
37+
|---|---|---|---|---|---|---|
38+
| moderate | [CVE-2026-48988](https://github.com/advisories/GHSA-6v5v-wf23-fmfq) | `markdown-it` | `14.1.1` | `lib__api-spec>orval>typedoc>markdown-it` | markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations ||
39+
| moderate | [CVE-2026-53550](https://github.com/advisories/GHSA-h67p-54hq-rp68) | `js-yaml` | `4.1.1` | `lib__api-spec>orval>js-yaml` | JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases ||
40+
| low | [CVE-2026-49356](https://github.com/advisories/GHSA-4x5r-pxfx-6jf8) | `@babel/core` | `7.29.0` | `artifacts__biometric-demo-video>@vitejs/plugin-react>@babel/core` | @babel/core: Arbitrary File Read via sourceMappingURL Comment ||

0 commit comments

Comments
 (0)