Skip to content

fix(deps): bump js-yaml to 4.3.1 closing CVE-2026-59870 (high) - #1225

Merged
Fmarzochi merged 1 commit into
mainfrom
fix/js-yaml-cve-2026-59870
Aug 7, 2026
Merged

fix(deps): bump js-yaml to 4.3.1 closing CVE-2026-59870 (high)#1225
Fmarzochi merged 1 commit into
mainfrom
fix/js-yaml-cve-2026-59870

Conversation

@Fmarzochi

@Fmarzochi Fmarzochi commented Aug 7, 2026

Copy link
Copy Markdown
Owner

What

Bumps js-yaml to 4.3.1 in the root and fuzz lockfiles, closing GHSA-5p4m-2wfm-xmqj (CVE-2026-59870, high severity: quadratic CPU consumption in omap resolution). Lockfile-only change inside the existing semver ranges; no code touched.

Why now

The advisory was published after the last green PR runs, so Security Scan / npm audit began failing on the post-merge run on main (run 31145010690).

Verification

npm audit --audit-level=high reports 0 vulnerabilities in both the root and fuzz directories on this branch.


Summary by cubic

Upgrade js-yaml to 4.3.1 to patch CVE-2026-59870 (high) and restore passing security scans. Lockfile-only update to package-lock.json in root and fuzz; no code changes.

Written for commit d0ac89b. Summary will update on new commits.

Review in cubic

Signed-off-by: Felipe Marzochi <fmarzochi@gmail.com>
@Fmarzochi
Fmarzochi enabled auto-merge (squash) August 7, 2026 04:01
@sonarqubecloud

sonarqubecloud Bot commented Aug 7, 2026

Copy link
Copy Markdown

@Fmarzochi
Fmarzochi merged commit ab0ed76 into main Aug 7, 2026
41 checks passed
@Fmarzochi
Fmarzochi deleted the fix/js-yaml-cve-2026-59870 branch August 7, 2026 04:08
@github-project-automation github-project-automation Bot moved this from Todo to Done in EGC Roadmap Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant