Skip to content

fix(deps): Patch high-severity advisories - #724

Open
Zee2413 wants to merge 1 commit into
aws-cloudformation:mainfrom
Zee2413:cve-fix
Open

fix(deps): Patch high-severity advisories#724
Zee2413 wants to merge 1 commit into
aws-cloudformation:mainfrom
Zee2413:cve-fix

Conversation

@Zee2413

@Zee2413 Zee2413 commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Summary

  • update brace-expansion 1.x to 1.1.18 and 2.x to 2.1.4 in both affected lockfiles
  • update js-yaml to 5.2.2 in both affected lockfiles
  • update tar to 7.5.21 to resolve an additional critical finding surfaced during validation

Security verification

  • all six high-severity Dependabot findings resolve to versions outside their vulnerable ranges
  • action: 0 high and 0 critical npm audit findings
  • guard: 0 npm audit findings

Validation

  • action: formatting, lint, 20 tests, bundle build, and bundle comparison pass
  • guard: lint, 5 tests, and TypeScript build pass
  • all 16 pull-request checks pass, including cross-platform builds, unit and integration tests, clippy, formatting, fuzzing, and install-script checks

Update brace-expansion and js-yaml to patched releases in the action and TypeScript dependency graphs. Also update tar to resolve the critical advisory found during audit validation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant