Skip to content

fix: upgrade js-yaml and nx security patches - #316

Merged
OnestarLee merged 2 commits into
mainfrom
codex/secure-4411-4450-dependencies
Aug 18, 2026
Merged

fix: upgrade js-yaml and nx security patches#316
OnestarLee merged 2 commits into
mainfrom
codex/secure-4411-4450-dependencies

Conversation

@OnestarLee

@OnestarLee OnestarLee commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Upgrade js-yaml 3.x from 3.15.0 to 3.15.1.
  • Upgrade js-yaml 4.x from 4.3.0 to 4.3.1.
  • Raise the scoped lerna/js-yaml override to the patched 4.x release.
  • Pin Lerna's nx dependency to 22.7.7 and regenerate its transitive lockfile entries.

Why

  • The installed js-yaml versions are vulnerable to quadratic CPU consumption while resolving crafted !!omap input.
  • nx 22.6.5 is affected by unsafe archive extraction in self-hosted remote cache restoration.

Impact

The changes affect monorepo build tooling only. Public UIKit APIs and runtime source code are unchanged.

Validation

  • yarn install --frozen-lockfile --ignore-scripts --non-interactive
  • yarn build
  • yarn test --runInBand — 34 suites passed, 190 tests passed
  • Verified js-yaml 3.15.1 / 4.3.1 and nx 22.7.7 in the lockfile.

Jira

Upgrade js-yaml to 3.15.1/4.3.1 for SECURE-4450 and Nx to 22.7.7 for SECURE-4411.
@upwind-code-us

upwind-code-us Bot commented Aug 18, 2026

Copy link
Copy Markdown

Upwind Upwind Code Scan - ⛔ Do Not Deploy

61 newly introduced vulnerabilities · 0 resolved · 61 total in this PR vs main

🔴 6 Critical | 🔶 28 High | 🟡 23 Medium | 🟢 4 Low


🔴 Critical · 6 findings
CVE Package Version Fix
CVE-2026-54906 concurrent-ruby 1.3.3 1.3.7
CVE-2026-45363 jwt 2.10.2 2.10.3
CVE-2026-33896 node-forge 1.3.1 1.4.0
CVE-2026-1525 undici 6.22.0 6.24.0
CVE-2026-33210 json 2.16.0 2.17.1.2
CVE-2026-45623 postcss 8.4.49 8.5.12

🔶 High · 28 findings
CVE Package Version Fix
CVE-2026-34601 @xmldom/xmldom 0.7.13 0.8.12
CVE-2026-35611 addressable 2.8.7 2.9.0
CVE-2026-33891 node-forge 1.3.1 1.4.0
CVE-2026-41673 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-73646 postcss 8.4.49 8.5.18
CVE-2026-2229 undici 6.22.0 6.24.0
CVE-2026-1528 undici 6.22.0 6.24.0
CVE-2026-41675 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-1526 undici 6.22.0 6.24.0
CVE-2026-41907 uuid 7.0.3 11.1.1
CVE-2026-41672 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-33176 activesupport 7.2.3 7.2.3.1
CVE-2026-54904 concurrent-ruby 1.3.3 1.3.7
CVE-2026-22036 undici 6.22.0 6.23.0
CVE-2026-12151 undici 6.22.0 6.27.0
CVE-2026-41675 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-2391 qs 6.13.0 6.14.2
CVE-2026-41674 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-41674 @xmldom/xmldom 0.7.13 0.8.13
CVE-2025-66031 node-forge 1.3.1 1.3.2
CVE-2026-41907 uuid 3.4.0 11.1.1
CVE-2026-41673 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-41672 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-54297 faraday 1.10.4 1.10.6
CVE-2026-33894 node-forge 1.3.1 1.4.0
CVE-2025-12816 node-forge 1.3.1 1.3.2
CVE-2026-33895 node-forge 1.3.1 1.4.0
CVE-2026-34601 @xmldom/xmldom 0.8.11 0.8.12

🟡 Medium · 23 findings
CVE Package Version Fix
CVE-2026-67213 nanoid 3.3.11 3.3.18
CVE-2026-16728 undici 6.22.0 6.28.0
CVE-2023-0842 xml2js 0.4.23 0.5.0
CVE-2026-9679 undici 6.22.0 6.27.0
CVE-2026-8723 qs 6.13.0 6.15.2
CVE-2026-12590 body-parser 1.20.3 1.20.6
CVE-2026-54171 excon 0.112.0 1.5.0
CVE-2026-25765 faraday 1.10.4 1.10.5
CVE-2026-33170 activesupport 7.2.3 7.2.3.1
CVE-2026-15157 undici 6.22.0 6.28.0
CVE-2026-33169 activesupport 7.2.3 7.2.3.1
CVE-2026-41650 fast-xml-parser 4.5.6 5.7.0
CVE-2026-69153 postcss 8.4.49 8.5.23
CVE-2026-47751 anthropics/claude-code-action v1 1.0.74
CVE-2025-14762 aws-sdk-s3 1.203.1 1.208.0
CVE-2026-67214 nanoid 3.3.11 3.3.16
CVE-2025-66030 node-forge 1.3.1 1.3.2
CVE-2026-53632 launch-editor 2.12.0 2.14.1
CVE-2026-16729 undici 6.22.0 6.28.0
CVE-2026-1527 undici 6.22.0 6.24.0
CVE-2026-41305 postcss 8.4.49 8.5.10
CVE-2026-54905 concurrent-ruby 1.3.3 1.3.7
CVE-2026-48038 joi 17.13.3 17.13.4

🟢 Low · 4 findings
CVE Package Version Fix
CVE-2026-6733 undici 6.22.0 6.27.0
CVE-2025-15284 qs 6.13.0 6.14.1
CVE-2026-54696 json 2.16.0 2.19.9
CVE-2026-11525 undici 6.22.0 6.27.0

View full analysis in Upwind Console

Scan completed in 61m 24s

Scan history (2 scans)
Commit Scanned at New Resolved Net
fc28410 2026-08-18 02:10 UTC +61 0 +61
214f1e8 < 2026-08-18 01:31 UTC +61 0 +61

Last scanned: 214f1e8 · 2026-08-18 01:31 UTC

@upwind-code-us

upwind-code-us Bot commented Aug 18, 2026

Copy link
Copy Markdown

Upwind Upwind IaC Scan - ✅ Proceed with Deployment

0 newly introduced misconfigurations · 0 resolved · 0 total in this PR vs main

View full analysis in Upwind Console →

Scan completed in 60m 26s

Scan history (2 scans)
Commit Scanned at New Resolved Net
fc28410 2026-08-18 02:14 UTC 0 0 0
214f1e8 < 2026-08-18 01:31 UTC 0 0 0

Last scanned: 214f1e8 · 2026-08-18 01:31 UTC

@codecov-commenter

codecov-commenter commented Aug 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 11.34%. Comparing base (7182978) to head (214f1e8).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #316   +/-   ##
=======================================
  Coverage   11.34%   11.34%           
=======================================
  Files         361      361           
  Lines        9105     9105           
  Branches     2568     2585   +17     
=======================================
  Hits         1033     1033           
  Misses       7996     7996           
  Partials       76       76           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@OnestarLee
OnestarLee marked this pull request as ready for review August 18, 2026 01:06
@OnestarLee
OnestarLee added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit b54c042 Aug 18, 2026
8 checks passed
@OnestarLee
OnestarLee deleted the codex/secure-4411-4450-dependencies branch August 18, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants