Repository navigation
fix(deps): update serialize-javascript to 7.1.2 - #40
Merged
Merged
Conversation
Resolves GHSA-gfhx-hw2g-v5hg (CVE-2026-97711), an XSS regression in 7.1.1 where a function body could carry an unescaped </script> into the output. It fails the dependency-audit job. copy-webpack-plugin and mocha already allow 7.1.2, so only the lockfile changes. The package is build and test tooling only and is not bundled into the extension or the server.
2 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
This PR addresses the second of the two findings that fail the
dependency-auditjob (run 36873323031); the first was fixed in #39.serialize-javascript7.1.1 is affected by GHSA-gfhx-hw2g-v5hg (CVE-2026-97711, low). It's a regression specific to 7.1.1: a crafted function body containing</scriptin code position could carry an unescaped</script>into the serialized output. 7.1.2 fixes it by tighteningSCRIPT_CLOSE_REGEXPfrom[^>]*to[^<>]*. It also makes the native-code check regex non-global and rejects atoString()that returns a non-string.The only dependents,
copy-webpack-plugin(^7.0.3) andmocha(^7.0.2), already allow 7.1.2. This is therefore a lockfile-only update of a single entry, made withnpm update serialize-javascript. 7.1.2 adds no dependencies or install scripts, and its npm provenance attests it was built fromyahoo/serialize-javascriptat tagv7.1.2.The package is build and test tooling only. It appears in none of the client or server bundle inventories and is not in the packaged VSIX, so the shipped extension is unaffected either way. The fix mainly clears the audit gate.
Verification
After a clean
npm cifrom the updated lockfile on Node 24.10.0 / npm 11.6.1,npm audit --audit-level=lowreports 0 vulnerabilities. I then ran the build job's steps locally and all of them passed:check-version-sync, the lockfile consistency check,build:types,lint,typescript:check-types,test:tooling,build:prod(which runscopy-webpack-plugin),check-attribution,test:browser,test:previews,npm run test(server unit tests and e2e under mocha, 0 failures),npm publish --dry-run --workspace=serverandvscode:package. The packagedvscode-openapi-toolkit-1.5.3.vsixhas sha2566d3f2ec4b0413cb6773ca01d8ade05fd31437824a27dc981469d7e0e17299d60.