Skip to content

Refresh yarn.lock: lodash, lodash-es, json5, braces, semver (Wiz #15) - #16

Open
claudesecuritypatcher[bot] wants to merge 1 commit into
mainfrom
wiz-remediation/issue-15
Open

claudesecuritypatcher[bot] wants to merge 1 commit into
mainfrom
wiz-remediation/issue-15

Conversation

@claudesecuritypatcher

Copy link
Copy Markdown

Closes #15

Fixes Wiz posture issue 5f20cf64-222b-4dd8-a6f4-0abe6700a3c0: CVE-2026-4800 (lodash, lodash-es), CVE-2022-46175 (json5), CVE-2024-4068 (braces) and CVE-2022-25883 (semver).

Why this matters

The worst of these is lodash's _.template, which can run injected code if untrusted strings end up as options.imports key names. The others are a json5 prototype pollution and two denial-of-service bugs, in braces and semver. None of them ship in the action: yarn why traces every one to the xo lint toolchain (eslint-import-resolver-webpack, eslint-plugin-unicorn, eslint-plugin-ava, babel). ncc only bundles @actions/* and @octokit/* into dist/index.js. They still run on CI runners and developer machines during yarn install and yarn run xo. Wiz rates lodash CRITICAL, and a lock refresh costs nothing, so I fixed them rather than deferring.

Risk of this change

This only changes yarn.lock. package.json is untouched. Every existing range (lodash@^4.17.21, json5@^1.0.1/^2.2.1, braces@^3.0.2, semver@^5.7.1/^6.0.0/^7.3.7) already allowed the fixed version, so the lock was just stale. Only those eight lock entries were re-resolved (fill-range moved along with braces, and semver 7 no longer needs lru-cache). The rest of the lock was left alone. A blanket yarn upgrade would have pulled in new runtime advisories through @actions/http-client. Because no override was added, Dependabot keeps these packages current.

This overlaps with Dependabot #6 (lodash-es only) and #10 (lodash and braces, bundled with an @octokit/request 6→8 major, CI red). Neither of those covers json5 or semver.

Verification

Ran the steps from test.yml locally: yarn install, yarn-deduplicate --fail --strategy fewer (exit 0), yarn run build (ncc, dist/index.js 546kB, exit 0), yarn run xo (exit 0). Resolved versions in the lock:

braces 3.0.3 · json5 1.0.2, 2.2.3 · lodash 4.18.1 · lodash-es 4.18.1 · semver 5.7.2, 6.3.1, 7.8.5

yarn audit --level high still lists a high braces advisory. It's a newer one with no patched release yet, not CVE-2024-4068. Runtime jsonwebtoken/jws are handled in #14. The Test check's Prettier step already fails on main, because of README.md since f61e816, so it isn't caused by this change.

🤖 Generated with Claude Code

In-range lock re-resolve, no manifest change: lodash/lodash-es 4.18.1
(CVE-2026-4800), json5 1.0.2/2.2.3 (CVE-2022-46175), braces 3.0.3
(CVE-2024-4068), semver 5.7.2/6.3.1/7.8.5 (CVE-2022-25883). All in the
xo lint tree only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claudesecuritypatcher

Copy link
Copy Markdown
Author

The red Test check has nothing to do with this PR. It fails at the Format step (prettier --check), which only flags README.md: [warn] README.md … Code style issues found (job log). This PR only changes yarn.lock. main's README.md (last changed in f61e816) fails prettier --check on its own, and the other open PR branches (wiz-remediation/issue-11 and both Dependabot PRs) fail Test the same way. The install, dedupe, build and xo steps all pass locally on this branch. I left the README alone because it's outside this security fix. Running yarn run prettier --write README.md on main will turn the check green.

@claudesecuritypatcher

Copy link
Copy Markdown
Author

Its own checks are failing

Test fails, so this PR cannot be merged as it stands. If the base has moved on since it was opened it may be obsolete; closing it with a one-line reason is a valid answer, and the finding returns to the automation against the current base.

Automated check on each sweep; this comment is rewritten in place. The security review, if any, is a separate comment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HIGH CVSS Exploitable CVE in Code Repository

0 participants