Repository navigation
Refresh yarn.lock: lodash, lodash-es, json5, braces, semver (Wiz #15) - #16
claudesecuritypatcher[bot] wants to merge 1 commit into
Conversation
In-range lock re-resolve, no manifest change: lodash/lodash-es 4.18.1 (CVE-2026-4800), json5 1.0.2/2.2.3 (CVE-2022-46175), braces 3.0.3 (CVE-2024-4068), semver 5.7.2/6.3.1/7.8.5 (CVE-2022-25883). All in the xo lint tree only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The red |
Its own checks are failingTest fails, so this PR cannot be merged as it stands. If the base has moved on since it was opened it may be obsolete; closing it with a one-line reason is a valid answer, and the finding returns to the automation against the current base. Automated check on each sweep; this comment is rewritten in place. The security review, if any, is a separate comment. |
Closes #15
Fixes Wiz posture issue
5f20cf64-222b-4dd8-a6f4-0abe6700a3c0: CVE-2026-4800 (lodash, lodash-es), CVE-2022-46175 (json5), CVE-2024-4068 (braces) and CVE-2022-25883 (semver).Why this matters
The worst of these is lodash's
_.template, which can run injected code if untrusted strings end up asoptions.importskey names. The others are a json5 prototype pollution and two denial-of-service bugs, in braces and semver. None of them ship in the action:yarn whytraces every one to thexolint toolchain (eslint-import-resolver-webpack, eslint-plugin-unicorn, eslint-plugin-ava, babel). ncc only bundles@actions/*and@octokit/*intodist/index.js. They still run on CI runners and developer machines duringyarn installandyarn run xo. Wiz rates lodash CRITICAL, and a lock refresh costs nothing, so I fixed them rather than deferring.Risk of this change
This only changes
yarn.lock.package.jsonis untouched. Every existing range (lodash@^4.17.21,json5@^1.0.1/^2.2.1,braces@^3.0.2,semver@^5.7.1/^6.0.0/^7.3.7) already allowed the fixed version, so the lock was just stale. Only those eight lock entries were re-resolved (fill-rangemoved along with braces, and semver 7 no longer needslru-cache). The rest of the lock was left alone. A blanketyarn upgradewould have pulled in new runtime advisories through@actions/http-client. Because no override was added, Dependabot keeps these packages current.This overlaps with Dependabot #6 (lodash-es only) and #10 (lodash and braces, bundled with an
@octokit/request6→8 major, CI red). Neither of those covers json5 or semver.Verification
Ran the steps from
test.ymllocally:yarn install,yarn-deduplicate --fail --strategy fewer(exit 0),yarn run build(ncc,dist/index.js546kB, exit 0),yarn run xo(exit 0). Resolved versions in the lock:yarn audit --level highstill lists a highbracesadvisory. It's a newer one with no patched release yet, not CVE-2024-4068. Runtimejsonwebtoken/jwsare handled in #14. TheTestcheck's Prettier step already fails onmain, because ofREADME.mdsince f61e816, so it isn't caused by this change.🤖 Generated with Claude Code