Skip to content

chore(security): bump js-yaml to 3.15.2 in website lockfile (GHSA-2883-xcg3-v3hh) - #10

Open
benfrank241 wants to merge 1 commit into
mainfrom
chore/security-daily-20260921-self-driving-agents-npm-website
Open

benfrank241 wants to merge 1 commit into
mainfrom
chore/security-daily-20260921-self-driving-agents-npm-website

Conversation

@benfrank241

Copy link
Copy Markdown
Member

Daily security sweep (2026-09-21) — npm, website/package-lock.json.

Advisories closed

Package From → To Advisory Severity
js-yaml 3.15.1 → 3.15.2 GHSA-2883-xcg3-v3hh high

js-yaml is transitive, pulled in through gray-matter (js-yaml ^3.13.1). 3.15.2 is the patched v3-legacy release, inside the range gray-matter declares.

No Dependabot alert numbers: this repo's Dependabot alerts endpoint returns zero alerts in every state, although npm audit reports real advisories. The advisory came from npm audit --package-lock-only and the GitHub Advisory DB. Recommend enabling Dependabot alerts under Settings → Code security.

Change

  • npm update --package-lock-only --ignore-scripts js-yaml. package.json is unchanged.
  • Lock diff: the js-yaml entry, plus npm dropping a stale "dev": true from postcss. postcss is a runtime dependency of next, so that flag was wrong. Normalization only; the version is unchanged.

Verification (local, npm 10.9.8 / node 22, same as pages.yml)

Baseline on main compared with this branch: npm ci ✓/✓, npm run build (next static export) ✓/✓, same route table. Lint was skipped because the website has no ESLint config, so next lint would prompt. npm audit goes from 1 high to 0.

Not merged. Needs review.

🤖 Generated with Claude Code

Fixes GHSA-2883-xcg3-v3hh (js-yaml, high) — transitive via gray-matter (js-yaml ^3.13.1).
In-range lockfile-only update; package.json unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@cdbartholomew cdbartholomew added the p1 Priority: high label Sep 23, 2026
@cdbartholomew cdbartholomew self-assigned this Sep 23, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

p1 Priority: high security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants