Skip to content

chore(security): js-yaml + nanoid highs (lockfile-only) - #1355

Merged
avifenesh merged 3 commits into
mainfrom
security/js-yaml-nanoid-20260810
Aug 13, 2026
Merged

chore(security): js-yaml + nanoid highs (lockfile-only)#1355
avifenesh merged 3 commits into
mainfrom
security/js-yaml-nanoid-20260810

Conversation

@avifenesh

Copy link
Copy Markdown
Collaborator

Lockfile-only bumps: js-yaml GHSA-5p4m-2wfm-xmqj (quadratic !!omap) + nanoid GHSA-2v37-7h3g-55p8. Remaining audit noise is unpatched image-size (no upstream fix) — expected nonzero audit, out of scope.

@revuto-review revuto-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an auto review done by revuto.


The website lockfile updates are internally consistent, but the changelog overstates the scope and exposes an omitted security bump in the second npm lockfile.

Comment thread CHANGELOG.md
## [Unreleased]

### Security
- **Dependency lockfile bumps (website + VS Code extension)**: js-yaml

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an auto review done by revuto.


This says the VS Code extension lockfile was bumped, but this PR changes only website/package-lock.json. editors/vscode/package-lock.json still pins node_modules/js-yaml to vulnerable 4.3.0 (lines 3201–3204), and the release workflow installs that lockfile with npm ci before packaging the extension. Please also update the VS Code lockfile to 4.3.1, or remove “+ VS Code extension” if this PR is intentionally website-only.

@avifenesh
avifenesh merged commit df3a415 into main Aug 13, 2026
15 checks passed
@avifenesh
avifenesh deleted the security/js-yaml-nanoid-20260810 branch August 13, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant