From ad76a2c22028b0bc5d54710067552be0235b62d3 Mon Sep 17 00:00:00 2001 From: Mihir Rawool Date: Mon, 21 Sep 2026 00:53:24 +0530 Subject: [PATCH] LTS-4981 / LTS-5094: bump fast-uri + js-yaml security floors - fast-uri: override floor 3.1.5 -> 3.1.6 (GHSA-5jgf-p345-68v8, CVE-2026-75931). 3.1.5 was itself still inside the vulnerable range (>=3.1.3, <3.1.6) for a host-confusion bug in resolve() on scheme-relative references; patched floors per advisory are 2.4.5 / 3.1.6 / 4.1.3, resolves to 3.1.8 in-tree. - js-yaml: version-scoped override floors bumped for both installed majors (GHSA-2883-xcg3-v3hh, CVE-2026-84375) - maxTotalMergeKeys doesn't count empty merge-source mappings, allowing O(N*K) CPU blowup: - js-yaml@3: ^3.15.1 -> ^3.15.2 (consumed by js-yaml-cloudformation-schema) - js-yaml@4: ^4.3.1 -> ^4.3.2 (direct + other transitive consumers) Kept the version-scoped override split from LTS-4699/4700 so the 3.x consumer isn't force-upgraded onto 4.x (safeLoad was removed in 4.x). Also converted the remaining exact-pinned overrides (qs, jws, fast-xml-builder, path-expression-matcher) to caret ranges - exact pins are exactly how fast-uri's prior override re-aged into a vulnerable range. Left `tmp` alone since it's covered by an unrelated open dependabot PR. Verified via `npm ci` from a clean install + `npm ls fast-uri/js-yaml --all`: the js-yaml 3.x consumer stays on 3.15.2 (not forced to 4.x), fast-uri resolves to 3.1.8, and `npm audit` no longer flags either package. Co-Authored-By: Claude Sonnet 5 --- package-lock.json | 18 +++++++++--------- package.json | 14 +++++++------- 2 files changed, 16 insertions(+), 16 deletions(-) diff --git a/package-lock.json b/package-lock.json index d7ac9c0..3b1252b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -5182,9 +5182,9 @@ "license": "MIT" }, "node_modules/fast-uri": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz", - "integrity": "sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==", + "version": "3.1.8", + "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.8.tgz", + "integrity": "sha512-GZMtZUTNRpOVIECoXwLNZS5xUGE+mVNbTB8h/7Rwh2TFWcBQiPzTgyZi05BF9UMZKkLJv8XBRJTlU7zg8+ZfMg==", "dev": true, "funding": [ { @@ -7398,9 +7398,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", - "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "version": "4.3.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz", + "integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==", "dev": true, "funding": [ { @@ -7441,9 +7441,9 @@ } }, "node_modules/js-yaml-cloudformation-schema/node_modules/js-yaml": { - "version": "3.15.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.1.tgz", - "integrity": "sha512-S99WuO3HlhO3XN41EtYUNl9zzXjoJx7QvmipxsJVxtCBT0YHEFy+iOJhjSvrmV12nYhWpZaM8lPHkJm0yUMbag==", + "version": "3.15.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.2.tgz", + "integrity": "sha512-6EuL879VkRA+1Cz578mKMiKvjPNEuk6+r1JaFzoSWejZmtf7xWbIyw1e3KkxlkzTIt9Taw6JBhEppG7utc1P+w==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index a7be281..bb873df 100644 --- a/package.json +++ b/package.json @@ -27,17 +27,17 @@ "mocha": "^10.8.2" }, "overrides": { - "qs": "6.14.2", - "jws": "4.0.1", + "qs": "^6.14.2", + "jws": "^4.0.1", "fast-xml-parser": "^5.10.1", "basic-ftp": "^5.3.1", - "fast-uri": "^3.1.5", + "fast-uri": "^3.1.6", "brace-expansion@1": "^1.1.18", "brace-expansion@2": "^2.1.4", - "js-yaml@3": "^3.15.1", - "js-yaml@4": "^4.3.1", - "fast-xml-builder": "1.2.1", - "path-expression-matcher": "1.6.1", + "js-yaml@3": "^3.15.2", + "js-yaml@4": "^4.3.2", + "fast-xml-builder": "^1.2.1", + "path-expression-matcher": "^1.6.1", "tmp": "0.2.7", "esbuild": "^0.28.1", "serialize-javascript": "^7.0.3",