Skip to content

chore: upgrade js-yaml to ^4.3.0 to address CVE-2026-59869#1470

Merged
jsourcebot merged 3 commits into
mainfrom
linear/sou-1551-sourcebot-devsourcebot-cve-2026-59869-js-yaml-js-yaml-5e0b
Jul 23, 2026
Merged

chore: upgrade js-yaml to ^4.3.0 to address CVE-2026-59869#1470
jsourcebot merged 3 commits into
mainfrom
linear/sou-1551-sourcebot-devsourcebot-cve-2026-59869-js-yaml-js-yaml-5e0b

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1551

Addresses CVE-2026-59869 (HIGH): js-yaml can spend quadratic CPU time parsing crafted YAML documents that chain merge keys, enabling a denial of service. Fixed in js-yaml 4.3.0.

All requesters (@apidevtools/json-schema-ref-parser, @eslint/eslintrc, json-schema-to-typescript) already declared ^4.1.x ranges that admit 4.3.0, so this is a lockfile refresh only (yarn up -R js-yaml) — no package.json or resolutions change needed. yarn why js-yaml confirms every instance now resolves to 4.3.0.


Note

Low Risk
Patch-level transitive dependency bump with no application code changes; low behavioral risk aside from YAML parsing hardening.

Overview
Bumps the transitive js-yaml dependency from 4.2.0 to 4.3.0 in yarn.lock to address CVE-2026-59869, where crafted YAML with chained merge keys could cause quadratic CPU use (DoS).

This is a lockfile-only refresh; existing ^4.1.x ranges on dependents already allow 4.3.0. The unreleased CHANGELOG notes the upgrade under Fixed.

Reviewed by Cursor Bugbot for commit 7ad8c5a. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2222
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 39

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.0.5 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.11 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/codemirror-lang-elixir LICENSE file, Apache-2.0)
khroma 2.1.0 UNKNOWN MIT GitHub repo (fabiospampinato/khroma, MIT)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/lezer-elixir LICENSE file, Apache-2.0)
map-stream 0.1.0 UNKNOWN MIT GitHub repo (dominictarr/map-stream, MIT)
memorystream 0.3.1 UNKNOWN MIT npm registry (legacy licenses field: [{"type":"MIT"}]) - extracted from object
pause-stream 0.0.11 ["MIT","Apache2"] MIT OR Apache-2.0 extracted from license array (npm registry) - dual-licensed MIT / Apache-2.0
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 GitHub repo (PostHog/posthog-js LICENSE file, Apache-2.0 primary; MIT for select vendored files)
valid-url 1.0.9 UNKNOWN MIT GitHub repo (ogt/valid-url LICENSE file, MIT)

@brendan-kellam
brendan-kellam marked this pull request as ready for review July 21, 2026 14:08
…ebot-devsourcebot-cve-2026-59869-js-yaml-js-yaml-5e0b

# Conflicts:
#	CHANGELOG.md
@jsourcebot
jsourcebot merged commit a536249 into main Jul 23, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant