Skip to content

fix: remediate js-yaml vulnerability - #132

Merged
dunice merged 1 commit into
mendr/repair/b1be3540-4bb1-4e1e-a3c5-f91ea1ea209dfrom
mendr/repair/ec3e8aa7-eb7f-48eb-9cd9-25d2e255cc65
Sep 16, 2026
Merged

dunice merged 1 commit into
mendr/repair/b1be3540-4bb1-4e1e-a3c5-f91ea1ea209dfrom
mendr/repair/ec3e8aa7-eb7f-48eb-9cd9-25d2e255cc65

Conversation

@mendr-app

@mendr-app mendr-app Bot commented Sep 16, 2026

Copy link
Copy Markdown

What changed

Updated the transitive js-yaml dependency from 4.1.1 to 4.3.2 in package-lock.json.

Validation

Repository setting: Agent decides. The agent chooses relevant checks. Observed results are reported below.

Passed npm ci, 44 tests, lint, dependency resolution, audit, and git diff checks. All requested js-yaml advisories are absent; one unrelated brace-expansion advisory remains.

Repository CI: Not yet verified by Mendr. Check this PR’s status checks before merging.

Security context

Remediate the reported vulnerabilities in js-yaml.

Reported advisories: GHSA-2883-xcg3-v3hh, GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68, CVE-2026-53550, CVE-2026-59869, CVE-2026-84375

Affected dependency files:

  • package-lock.json
Independent AI review

The lockfile-only update correctly upgrades the sole js-yaml instance from 4.1.1 to 4.3.2. All four requested advisory ranges are remediated, dependency resolution is consistent, and recorded npm ci, 44 tests, and lint checks passed. Audit reports no js-yaml findings; one unrelated brace-expansion advisory remains.

Execution details
Recorded results Exit 0 Nonzero or unconfirmed
23 20 3

These counts include investigation, setup, checks, and cleanup. They are not a test pass rate. Full command output is retained in the Mendr repair record.

Base: f472c2f
Reviewed commit: 53070fd
Repair run: ec3e8aa7-eb7f-48eb-9cd9-25d2e255cc65

Review in cubic

Mendr repair ec3e8aa7-eb7f-48eb-9cd9-25d2e255cc65
@dunice
dunice changed the base branch from master to mendr/repair/b1be3540-4bb1-4e1e-a3c5-f91ea1ea209d September 16, 2026 21:52
@dunice
dunice marked this pull request as ready for review September 16, 2026 21:52
@dunice
dunice merged commit 7fc5604 into mendr/repair/b1be3540-4bb1-4e1e-a3c5-f91ea1ea209d Sep 16, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant