Skip to content

fix(deps): vuln minor upgrades — 12 packages (minor: 6 · patch: 6) - #1373

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1786950220
Open

fix(deps): vuln minor upgrades — 12 packages (minor: 6 · patch: 6) #1373
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1786950220

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Critical-severity security update — 15 packages upgraded (MINOR changes included)

Manifests changed:

  • . (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

PackageFromToTypeDep TypeVulnerabilities Fixed
tar7.5.167.5.22patchTransitive2 CRITICAL, 2 HIGH, 6 MEDIUM
brace-expansion2.0.32.1.4minorTransitive6 HIGH
brace-expansion5.0.65.0.9patchTransitive6 HIGH
brace-expansion1.1.131.1.18patchTransitive6 HIGH
fast-uri3.1.23.1.5patchTransitive6 HIGH
js-yaml4.1.04.3.1minorTransitive3 HIGH, 4 MEDIUM
js-yaml3.14.23.15.1minorTransitive3 HIGH, 2 MEDIUM
axios1.16.01.19.0minorTransitive2 HIGH, 18 MEDIUM
glob11.0.311.1.0minorTransitive2 HIGH
shell-quote1.8.41.10.0minorTransitive2 HIGH
sigstore4.0.04.1.1minorTransitive2 HIGH
minimatch3.1.33.1.5patchTransitive2 HIGH
tmp0.2.60.2.7patchTransitive2 HIGH
fast-xml-parser4.5.54.5.7patchTransitive2 MEDIUM
protobufjs7.6.37.6.5patchTransitive2 MEDIUM

Security Details

🚨 Critical & High Severity (46 fixed)
PackageCVESeveritySummaryUnsafe VersionFixed InCase
tarCVE-2026-59873CRITICALnode-tar: Decompression/parse DoS via unlimited input7.5.16--
tarGHSA-23hp-3jrh-7fpwCRITICALnode-tar: Decompression/parse DoS via unlimited input7.5.167.5.19-
axiosGHSA-gcfj-64vw-6mp9HIGHAxios Node HTTP adapter can use an inherited proxy after interceptor config cloning1.16.00.33.0-
axiosCVE-2026-67320HIGHaxios before 0.33.0 Prototype Pollution via Node HTTP adapter1.16.0--
brace-expansionGHSA-mh99-v99m-4gvgHIGHbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash1.1.135.0.8-
brace-expansionCVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crash5.0.6--
brace-expansionGHSA-3jxr-9vmj-r5cpHIGHbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups1.1.135.0.7-
brace-expansionCVE-2026-13149HIGH-1.1.13--
brace-expansionGHSA-rgw5-rvv9-x895HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation1.1.131.1.18-
brace-expansionCVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crash1.1.13--
brace-expansionGHSA-3jxr-9vmj-r5cpHIGHbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups2.0.35.0.7-
brace-expansionCVE-2026-13149HIGH-5.0.6--
brace-expansionGHSA-3jxr-9vmj-r5cpHIGHbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups5.0.65.0.7-
brace-expansionCVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation1.1.13--
brace-expansionGHSA-mh99-v99m-4gvgHIGHbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash5.0.65.0.8-
brace-expansionCVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation5.0.6--
brace-expansionGHSA-rgw5-rvv9-x895HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation5.0.61.1.18-
brace-expansionCVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crash2.0.3--
brace-expansionGHSA-mh99-v99m-4gvgHIGHbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash2.0.35.0.8-
brace-expansionCVE-2026-13149HIGH-2.0.3--
brace-expansionGHSA-rgw5-rvv9-x895HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation2.0.31.1.18-
brace-expansionCVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation2.0.3--
fast-uriGHSA-4c8g-83qw-93j6HIGHfast-uri vulnerable to host confusion via failed IDN canonicalization3.1.24.0.1-
fast-uriGHSA-7p8r-x3mc-p8w7HIGHfast-uri vulnerable to host confusion via backslash authority introducer3.1.22.4.4-
fast-uriCVE-2026-13676HIGHfast-uri vulnerable to host confusion via failed IDN canonicalization3.1.2--
fast-uriCVE-2026-18446HIGHfast-uri vulnerable to host confusion via backslash authority introducer3.1.2--
fast-uriGHSA-v2hh-gcrm-f6hxHIGHfast-uri vulnerable to host confusion via literal backslash authority delimiter3.1.22.4.3-
fast-uriCVE-2026-16221HIGHfast-uri vulnerable to host confusion via literal backslash authority delimiter3.1.2--
globGHSA-5j98-mcp5-4vw2HIGHglob CLI: Command injection via -c/--cmd executes matches with shell:true11.0.311.1.0-
globCVE-2025-64756HIGHglob CLI: Command injection via -c/--cmd executes matches with shell:true11.0.3--
js-yamlGHSA-5p4m-2wfm-xmqjHIGHJS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported4.1.04.3.1-
js-yamlGHSA-52cp-r559-cp3mHIGHjs-yaml: YAML merge-key chains can force quadratic CPU consumption3.14.23.15.0-
js-yamlCVE-2026-59869HIGHjs-yaml: YAML merge-key chains can force quadratic CPU consumption3.14.2--
js-yamlGHSA-52cp-r559-cp3mHIGHjs-yaml: YAML merge-key chains can force quadratic CPU consumption4.1.03.15.0-
js-yamlCVE-2026-59869HIGHjs-yaml: YAML merge-key chains can force quadratic CPU consumption4.1.0--
js-yamlGHSA-5p4m-2wfm-xmqjHIGHJS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported3.14.24.3.1-
minimatchCVE-2026-27904HIGHminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions3.1.3--
minimatchGHSA-23c5-xmqv-rm74HIGHminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions3.1.310.2.3-
shell-quoteGHSA-395f-4hp3-45gvHIGHshell-quote: Quadratic-complexity Denial of Service in parse() (CWE-407)1.8.41.9.0-
shell-quoteCVE-2026-13311HIGHshell-quote parse() is quadratic in token count, enabling denial of service1.8.4--
sigstoreGHSA-52v5-jr5w-gjxrHIGHsigstore's certificateOIDs verification constraints are silently dropped and never enforced4.0.04.1.1-
sigstoreCVE-2026-48815HIGHsigstore-js: certificateOIDs verification constraints are silently dropped and never enforced4.0.0--
tarCVE-2026-59874HIGHnode-tar: Negative tar entry size causes infinite loop in archive replace7.5.16--
tarGHSA-8x88-c5mf-7j5wHIGHnode-tar: Negative tar entry size causes infinite loop in archive replace7.5.167.5.18-
tmpCVE-2026-49982HIGHtmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/template0.2.6--
tmpGHSA-7c78-jf6q-g5cmHIGHtmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template0.2.60.2.7-
ℹ️ Other Vulnerabilities (34)
PackageCVESeveritySummaryUnsafe VersionFixed InCase
axiosCVE-2026-67312MODERATEaxios 0.28.0 before 0.33.0 Denial of Service via formToJSON1.16.0--
axiosCVE-2026-67321MODERATEaxios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass1.16.0--
axiosGHSA-xj6q-8x83-jv6gMODERATEAxios: Prototype pollution auth subfields can inject Basic auth1.16.01.18.0-
axiosCVE-2026-67317MODERATEaxios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream1.16.0--
axiosGHSA-jqh4-m9w3-8hp9MODERATEAxios: Fetch adapter ReadableStream uploads bypass maxBodyLength1.16.01.18.0-
axiosGHSA-hcpx-6fm6-wx23MODERATEAxios form serializer maxDepth bypass via {} metatoken1.16.00.33.0-
axiosGHSA-pmv8-rq9r-6j72MODERATEAxios: Deep formToJSON Key Recursion Can Cause Denial of Service1.16.00.33.0-
axiosCVE-2026-67316MODERATEaxios before 1.18.0 Prototype Pollution via bodyless methods1.16.0--
axiosGHSA-mmx7-hfxf-jppxMODERATEAxios: Prototype pollution gadgets can alter axios request construction1.16.01.18.0-
axiosCVE-2026-67314MODERATEaxios before 1.18.0 Prototype Pollution via auth subfields1.16.0--
axiosGHSA-mwf2-3pr3-8698MODERATEAxios: HTTP/2 streamed uploads bypass maxBodyLength1.16.01.18.0-
axiosCVE-2026-67318MODERATEaxios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/21.16.0--
axiosCVE-2026-67313MODERATEaxios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON1.16.0--
axiosCVE-2026-67315MODERATEaxios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.01.16.0--
axiosGHSA-42h9-826w-cgv3MODERATEAxios: Excessive recursion in formDataToJSON can cause denial of service1.16.00.33.0-
axiosGHSA-7q8q-rj6j-mhjqMODERATEAxios: Nested axios option objects can consume polluted prototype values1.16.00.33.0-
axiosCVE-2026-67319MODERATEaxios before 0.33.0 Prototype Pollution via nested option objects1.16.0--
axiosGHSA-f4gw-2p7v-4548MODERATEAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios1.16.01.18.0-
fast-xml-parserCVE-2026-41650MODERATEfast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters4.5.5--
fast-xml-parserGHSA-gh4j-gqv2-49f6MODERATEfast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters4.5.55.7.0-
js-yamlCVE-2025-64718MODERATEjs-yaml has prototype pollution in merge (<<)4.1.0--
js-yamlCVE-2026-53550MODERATEjs-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases4.1.0--
js-yamlGHSA-h67p-54hq-rp68MODERATEJS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases3.14.24.2.0-
js-yamlCVE-2026-53550MODERATEjs-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases3.14.2--
js-yamlGHSA-h67p-54hq-rp68MODERATEJS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases4.1.04.2.0-
js-yamlGHSA-mh29-5h37-fv8mMODERATEjs-yaml has prototype pollution in merge (<<)4.1.04.1.1-
protobufjsGHSA-j3f2-48v5-ccwwMODERATEprotobufjs: Denial of Service via infinite loop in .proto option parsing7.6.37.6.5-
protobufjsCVE-2026-59877MODERATEprotobufjs: Denial of Service via infinite loop in .proto option parsing7.6.3--
tarGHSA-w8wr-v893-vjvpMODERATEnode-tar: Process crash via PAX numeric path type confusion7.5.167.5.18-
tarCVE-2026-59871MODERATEnode-tar: Process crash via PAX numeric path type confusion7.5.16--
tarGHSA-gvwx-54wh-qm9jMODERATEnode-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records7.5.167.5.17-
tarCVE-2026-59875MODERATEnode-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records7.5.16--
tarCVE-2026-73566MODERATEnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection7.5.16--
tarGHSA-r292-9mhp-454mMODERATEnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection7.5.167.5.21-

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates the Node/Yarn dependency graph by refreshing multiple transitive package versions and adding/adjusting package overrides in package.json, with the corresponding yarn.lock regeneration.

Changes:

  • Bumped several pinned packages (e.g., axios, fast-xml-parser, tar, protobufjs) and refreshed the lockfile.
  • Added new override entries for glob, js-yaml, and sigstore using the npm: protocol.
  • Consolidated/rewired multiple dependency selectors in yarn.lock to newer resolved versions.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 5 comments.

FileDescription
yarn.lockRegenerated lockfile reflecting updated/merged resolutions and new transitive dependencies.
package.jsonUpdated version constraints and added new npm:-style override entries for specific packages.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadpackage.json
"fast-xml-parser": "4.5.5",
"axios": "1.16.0",
"fast-xml-parser": "^4.5.7",
"axios": "^1.19.0",
Comment threadpackage.json
"form-data": "4.0.6",
"on-headers": "1.1.0",
"tmp": "0.2.6",
"tmp": ">=0.2.7",
Comment threadpackage.json
"protobufjs": "^7.6.5",
"@protobufjs/utf8": "1.1.1",
"tar": "7.5.16",
"tar": "^7.5.22",
Comment threadpackage.json
"follow-redirects": "1.16.0",
"joi": "17.13.4",
"fast-uri": "3.1.2",
"fast-uri": "^3.1.5",
Comment threadpackage.json
"js-yaml@npm:^4.1.0": "npm:^4.3.1",
"js-yaml@npm:^3.10.0": "npm:^3.15.1",
"js-yaml@npm:^3.13.1": "npm:^3.15.1",
"sigstore@npm:^4.0.0": "npm:^4.1.1"
dd-octo-sts-6cbbf8Botand others added 2 commits August 24, 2026 21:38
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
ContributorAuthor

Auto-rebase complete

Branch is up to date with develop — rebased onto df00559.


Auto-Rebase · Add no-auto-rebase to opt out

CopilotAI review requested due to automatic review settings August 24, 2026 21:39
@dd-octo-sts-6cbbf8
dd-octo-sts-6cbbf8Botforce-pushed the engraver-auto-version-upgrade/minorpatch/npm/0-1786950220 branch from 79278eb to e3b45cbCompareAugust 24, 2026 21:39

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

Suppressed comments (2)

package.json:113

  • Using a broad >=0.2.7 range in resolutions.tmp can allow unexpected major upgrades (e.g., 1.x) on a future re-lock/install, which is risky for a security-focused patch PR. Prefer pinning to the intended safe version (e.g., 0.2.7) or a bounded range (^0.2.7 / ~0.2.7) and regenerate the lockfile.
 "tmp": ">=0.2.7",

package.json:138

  • The new resolutions entries for glob/js-yaml/sigstore don’t appear to take effect: yarn.lock still resolves glob@npm:^11.0.3 to 11.0.3 (yarn.lock:10220), js-yaml@npm:^4.1.0 to 4.1.1 and js-yaml@npm:^3.10.0 to 3.14.2 (yarn.lock:12074/12062), and sigstore@npm:^4.0.0 to 4.0.0 (yarn.lock:16870). This likely means the vulnerability fixes listed in the PR description are not actually applied.

Please adjust these resolutions to valid/explicit target versions (and/or syntax) and regenerate yarn.lock so the lockfile reflects the intended upgraded versions.

 "glob@npm:^11.0.3": "npm:^11.1.0",
"js-yaml@npm:^4.1.0": "npm:^4.3.1",
"js-yaml@npm:^3.10.0": "npm:^3.15.1",
"js-yaml@npm:^3.13.1": "npm:^3.15.1",
"sigstore@npm:^4.0.0": "npm:^4.1.1"

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant