Repository navigation
fix(deps): patch js-yaml and svgo advisories blocking Security Scanning #2089
Description
Activity
- addedtriagedItem has been triagedItem has been triagedpriority/p0Drop everything; same-day fixDrop everything; same-day fixseverity/highSignificant harmSignificant harmurgency/nowDrop other thingsDrop other thingsimpact/internalTeam-internal onlyTeam-internal onlyeffort/sHoursHourstype/securitySecurity findingSecurity finding
on Sep 9, 2026 Prepared local commit 2751481 on fix/npm-yaml-svgo-advisories: only frontend/package-lock.json changes (32 additions, 19 deletions). Native macOS Node 26.8.1 verification passed: baseline audit reproduced two high-severity vulnerable packages; updated full audit reports zero vulnerabilities; npm ci --ignore-scripts, production build, typecheck, lint and all 90 Jest suites passed (2890 tests, one skipped). Build retains its entrypoint-size warning and lint reports 125 existing warnings. Normal git-secrets/Trivy commit hooks passed without bypasses. The clean commit is held locally, not pushed or merged. Node 24 CI, substantive CodeRabbit and the exact final-head Fable 5.1 review remain pending; Fable capacity is currently unavailable. This dependency fix must land before PR #2071 can rebase and repeat its final gates.
Merged via PR #2090 as
5405fd1e90dffdb701a46d4b93868b947e1fbf05on 2026-09-11 at 16:48:11 UTC.Verified: fetched origin/main and compared Git trees. The merge commit and reviewed PR head
3f74875049e191c7c27e829b50fc78c346807ba0both have tree8b9612dd17e56b9134f8bfc17c7c40b0141ed6cd. Thus the earlier native build/Jest consumer verification applies to identical files. A fresh native macOS Node 26.8.1npm audit --audit-level=highreturnedfound 0 vulnerabilities(exit 0), and the isolated worktree remains clean. No dependencies were reinstalled.Main-branch verification is still pending: individual background watchers cover all nine workflows at the exact merge SHA, including the automatically triggered deployment workflows. Prior PR CI success is not being treated as main CI success. No deployed-browser or live-cloud test has been performed, and this agent has not initiated a deployment.
Follow-up: existing LeanerCloud/cloud-commitments-platform#74 now tracks the transient govulncheck network failures observed during PR verification. No duplicate issue was created. The issue's closed state came from the PR closing reference; this comment records the actual verification boundary. A terminal main-workflow result will follow.
Post-merge verification complete for PR #2090, squash commit
5405fd1e90dffdb701a46d4b93868b947e1fbf05.All nine exact-merge-SHA workflows completed successfully:
Workflow Run CI - Build & Test 34624083161 frontend-build-sentinel 34624083174 Frontend E2E 34624083239 pre-commit 34624083179 AWS Sanity (Read-only Dry Run) 34624083108 Azure Sanity (Read-only Dry Run) 34624083181 Deploy to AWS Lambda 34624083168 Deploy to GCP Cloud Run 34624083164 Deploy to Azure Container Apps 34624083243 The merge tree equals the reviewed PR-head tree:
8b9612dd17e56b9134f8bfc17c7c40b0141ed6cd. Earlier native Node 26 build/Jest consumer evidence therefore applies to identical files. A fresh native macOS Node 26.8.1npm audit --audit-level=highagain returnedfound 0 vulnerabilities, exit 0. The isolated worktree remains preserved; no dependencies were reinstalled and no source changes were made during post-merge verification.The deployment results above are GitHub Actions conclusions only. No independent deployed-browser or live-cloud test was performed, and this agent did not initiate deployments or cloud mutations. This dependency/configuration issue can remain closed based on the verified audit fix, identical reviewed tree and successful main workflows.
Follow-up issues filed: none. Existing LeanerCloud/cloud-commitments-platform#74 was updated by the parent with the earlier proxy download-failure evidence and retriaged; it tracks that separate network-resilience concern without a duplicate issue. All watcher logs remain preserved at
/private/tmp/claude/cudly-2089-ci-<run-id>.log, together with the earlier attempt-specific failure logs.- added a commit that references this issue
on Sep 27, 2026
The frontend lockfile on main at eac9a62 contains js-yaml 3.15.1 and 4.3.1 plus svgo 4.0.2. Running npm audit --audit-level=high reports two high-severity vulnerable packages and exits 1, blocking Security Scanning and CI Success. PR2071 run34415153948 reproduces this with a lockfile identical to main.
Current advisories:
Update frontend/package-lock.json within the existing parent ranges, including SVGO's required selector dependencies. Preserve package.json and the full-tree audit gate. Verify audit red before and green after, production frontend build, and Jest.
Related LeanerCloud/cloud-commitments-platform#79 covers earlier fast-uri/SVGO advisories; LeanerCloud/cloud-commitments-platform#165 covers the broader gating policy. Neither tracks these current advisory versions. All affected entries are dev dependencies; this report establishes CI failure and vulnerable installed versions, not production exploitability.