Skip to content

UID2-7538/7539/7540/7541: bump axios, brace-expansion, js-yaml, shell-quote (trivy HIGH CVEs)#251

Merged
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7538-vuln-npm-bumps
Jul 22, 2026
Merged

UID2-7538/7539/7540/7541: bump axios, brace-expansion, js-yaml, shell-quote (trivy HIGH CVEs)#251
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7538-vuln-npm-bumps

Conversation

@mcollins-ttd

Copy link
Copy Markdown
Contributor

Fixes the axios HIGH finding flagged by the scheduled scan, plus proactively bumps three transitive deps hit by the same CVEs so the next scan stays green.

CVE/GHSA Package Fix Jira
GHSA-gcfj-64vw-6mp9 axios →>=1.18.0 UID2-7538
CVE-2026-13149 brace-expansion v1→1.1.16, v2→2.1.2 UID2-7539
CVE-2026-59869 js-yaml v3→3.15.0 UID2-7540
CVE-2026-13311 shell-quote v1→1.9.0 UID2-7541

package-lock.json regenerated via major-scoped overrides; no vulnerable versions remain.

mcollins-ttd and others added 2 commits July 22, 2026 01:45
…-quote (trivy HIGH CVEs)

- GHSA-gcfj-64vw-6mp9: axios direct dep -> >=1.18.0
- CVE-2026-13149: brace-expansion v1 -> 1.1.16, v2 -> 2.1.2
- CVE-2026-59869: js-yaml v3 -> 3.15.0
- CVE-2026-13311: shell-quote v1 -> 1.9.0

axios was the scan-flagged finding; the other three are the same CVEs proactively bumped. package-lock.json regenerated via major-scoped overrides.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CVE-2026-59869 fixes the 4.x line at 4.3.0 as well as 3.15.0 for 3.x. The initial commit only pinned v3; js-yaml 4.1.1 was still present and flagged. Added a major-scoped js-yaml@4 -> 4.3.0 override and regenerated the lockfile(s).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@mcollins-ttd
mcollins-ttd merged commit 6048b60 into main Jul 22, 2026
4 checks passed
@mcollins-ttd
mcollins-ttd deleted the mkc-UID2-7538-vuln-npm-bumps branch July 22, 2026 05:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants