Skip to content

fix(deps): update serialize-javascript to 7.1.2 - #40

Merged
frantuma merged 1 commit into
mainfrom
fix/serialize-javascript-xss-advisory
Oct 5, 2026
Merged

frantuma merged 1 commit into
mainfrom
fix/serialize-javascript-xss-advisory

Conversation

@frantuma

@frantuma frantuma commented Oct 2, 2026

Copy link
Copy Markdown
Member

Change

This PR addresses the second of the two findings that fail the dependency-audit job (run 36873323031); the first was fixed in #39. serialize-javascript 7.1.1 is affected by GHSA-gfhx-hw2g-v5hg (CVE-2026-97711, low). It's a regression specific to 7.1.1: a crafted function body containing </script in code position could carry an unescaped </script> into the serialized output. 7.1.2 fixes it by tightening SCRIPT_CLOSE_REGEXP from [^>]* to [^<>]*. It also makes the native-code check regex non-global and rejects a toString() that returns a non-string.

The only dependents, copy-webpack-plugin (^7.0.3) and mocha (^7.0.2), already allow 7.1.2. This is therefore a lockfile-only update of a single entry, made with npm update serialize-javascript. 7.1.2 adds no dependencies or install scripts, and its npm provenance attests it was built from yahoo/serialize-javascript at tag v7.1.2.

The package is build and test tooling only. It appears in none of the client or server bundle inventories and is not in the packaged VSIX, so the shipped extension is unaffected either way. The fix mainly clears the audit gate.

Verification

After a clean npm ci from the updated lockfile on Node 24.10.0 / npm 11.6.1, npm audit --audit-level=low reports 0 vulnerabilities. I then ran the build job's steps locally and all of them passed: check-version-sync, the lockfile consistency check, build:types, lint, typescript:check-types, test:tooling, build:prod (which runs copy-webpack-plugin), check-attribution, test:browser, test:previews, npm run test (server unit tests and e2e under mocha, 0 failures), npm publish --dry-run --workspace=server and vscode:package. The packaged vscode-openapi-toolkit-1.5.3.vsix has sha256 6d3f2ec4b0413cb6773ca01d8ade05fd31437824a27dc981469d7e0e17299d60.

  • Examples and attachments are suitable for public disclosure.
  • User-facing documentation reflects the change (no user-facing behavior change).

Resolves GHSA-gfhx-hw2g-v5hg (CVE-2026-97711), an XSS regression in 7.1.1
where a function body could carry an unescaped </script> into the output.
It fails the dependency-audit job.

copy-webpack-plugin and mocha already allow 7.1.2, so only the lockfile
changes. The package is build and test tooling only and is not bundled into
the extension or the server.
@frantuma
frantuma requested a review from char0n as a code owner October 2, 2026 13:19
@frantuma
frantuma merged commit 10039d2 into main Oct 5, 2026
5 checks passed
@frantuma
frantuma deleted the fix/serialize-javascript-xss-advisory branch October 5, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant