Skip to content

fix(deps): resolve vitest/mocker path traversal and js-yaml DoS advisories - #20

Merged
mizcausevic-dev merged 1 commit into
mainfrom
fix/vitest-jsyaml-security-alerts
Sep 13, 2026
Merged

mizcausevic-dev merged 1 commit into
mainfrom
fix/vitest-jsyaml-security-alerts

Conversation

@mizcausevic-dev

Copy link
Copy Markdown
Owner

Summary

Test plan

Ran the full CI pipeline locally end to end on the resolved dependency tree:

  • npm run lint
  • npm run typecheck
  • npm run coverage (24 tests passing)
  • npm run build
  • npm run demo
  • npm audit --audit-level=high -> 0 vulnerabilities

Supersedes #13, which stays open with a comment explaining the narrower fix; safe to close once this merges.

🤖 Generated with Claude Code

…ories

Bumps vitest and @vitest/coverage-v8 to 4.1.11, the first version that
patches GHSA-82fw-gwwq-j7x9 (Path Traversal / Arbitrary File Read via
@vitest/mocker Redirect Mock), same fix Dependabot PR #13 targets, but
staying on the 4.x line instead of jumping to 5.0.0. vitest 5.0.0
requires Node >=22.12, which would break the node-20 leg of this repo's
CI matrix and its own engines.node >=20; 4.1.11 has no such requirement
and resolves both open vitest alerts (#21, #22) cleanly.

Adds an npm override pinning js-yaml to ^4.3.2, patching
GHSA-2883-xcg3-v3hh (#24, High). js-yaml is a transitive dev-only
dependency via eslint -> @eslint/eslintrc, not reachable from any
shipped code path, but it was failing the npm audit --audit-level=high
CI gate.

Verified locally end to end: lint, typecheck, coverage (24 tests),
build, demo, and npm audit --audit-level=high all pass with 0
vulnerabilities reported.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mizcausevic-dev
mizcausevic-dev merged commit bef9de6 into main Sep 13, 2026
4 checks passed
@mizcausevic-dev
mizcausevic-dev deleted the fix/vitest-jsyaml-security-alerts branch September 13, 2026 20:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant