diff --git a/CHANGELOG.md b/CHANGELOG.md index 2e4a2fe7..259d455f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -23,6 +23,7 @@ ### Security +- **Resolved js-yaml high-severity advisory CVE-2026-84375** (fixed in js-yaml >= 4.3.2 on the 4.x line and >= 3.15.2 on the 3.x line). js-yaml is only a transitive devDependency here — pulled on the 4.x line via `cosmiconfig` and on the 3.x line via `@istanbuljs/load-nyc-config`. Added scoped npm `overrides` (`cosmiconfig` → `js-yaml ^4.3.2`, `@istanbuljs/load-nyc-config` → `js-yaml ^3.15.2`) so each consumer stays on its own patched line. `npm audit` reports 0 vulnerabilities. - **Closed GHSA-r292-9mhp-454m (node-tar uncontrolled recursion, high, stack-overflow DoS via crafted long-path tar).** Bundled `tar` (pulled in transitively via the `npm` CLI devDependency, itself pulled in via `@semantic-release/npm`) was at 7.5.19/7.5.20, just short of the 7.5.21 patch. A plain `npm audit fix` (no `--force`) re-resolved `npm` to 11.19.1 (bundled tar 7.5.22) within the existing declared range — lockfile-only change, no `package.json`/direct-dependency edits, no semver-major bump. `npm audit`'s own suggested remediation path (`semantic-release@24.2.9`, flagged `isSemVerMajor`) was a red herring — the currently-resolved `semantic-release` (25.0.3, newer than that suggestion) was never at risk and is unchanged by this fix. - Correcting the note above (added 2026-05-20): the 2 remaining moderate advisories it described as needing a breaking `--force` change (`brace-expansion`, `ip-address`) are also resolved now — same non-force `npm audit fix`, same transitive-`npm`-CLI path. `npm audit` reports 0 vulnerabilities as of this change. diff --git a/package-lock.json b/package-lock.json index 4d0ed090..c1b7ee5c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1369,9 +1369,9 @@ } }, "node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml": { - "version": "3.15.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.1.tgz", - "integrity": "sha512-S99WuO3HlhO3XN41EtYUNl9zzXjoJx7QvmipxsJVxtCBT0YHEFy+iOJhjSvrmV12nYhWpZaM8lPHkJm0yUMbag==", + "version": "3.15.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.2.tgz", + "integrity": "sha512-6EuL879VkRA+1Cz578mKMiKvjPNEuk6+r1JaFzoSWejZmtf7xWbIyw1e3KkxlkzTIt9Taw6JBhEppG7utc1P+w==", "dev": true, "license": "MIT", "dependencies": { @@ -8575,9 +8575,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", - "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "version": "4.3.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz", + "integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==", "dev": true, "funding": [ { diff --git a/package.json b/package.json index 379dd051..3fb792f6 100644 --- a/package.json +++ b/package.json @@ -153,6 +153,12 @@ "diff": "^8.0.3", "@isaacs/brace-expansion": "^5.0.1", "uuid": "^14.0.2", - "qs": "^6.16.0" + "qs": "^6.16.0", + "cosmiconfig": { + "js-yaml": "^4.3.2" + }, + "@istanbuljs/load-nyc-config": { + "js-yaml": "^3.15.2" + } } }