Skip to content

UID2-7539/7540/7541: bump brace-expansion, js-yaml, shell-quote (trivy HIGH CVEs)#1047

Merged
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7539-vuln-npm-bumps
Jul 22, 2026
Merged

UID2-7539/7540/7541: bump brace-expansion, js-yaml, shell-quote (trivy HIGH CVEs)#1047
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7539-vuln-npm-bumps

Conversation

@mcollins-ttd

Copy link
Copy Markdown
Contributor

Fixes three HIGH trivy findings (build-time transitive npm deps) via major-scoped overrides + lockfile regen.

CVE Package Fix Jira
CVE-2026-13149 brace-expansion fixed patch per major UID2-7539
CVE-2026-59869 js-yaml v3→3.15.0 UID2-7540
CVE-2026-13311 shell-quote v1→1.9.0 UID2-7541

package-lock.json regenerated; no vulnerable versions remain. Major-scoped overrides leave healthy majors (e.g. js-yaml 4.x) untouched.

mcollins-ttd and others added 2 commits July 22, 2026 01:45
…y HIGH CVEs)

- CVE-2026-13149: brace-expansion -> fixed patch (major-scoped override)
- CVE-2026-59869: js-yaml v3 -> 3.15.0
- CVE-2026-13311: shell-quote v1 -> 1.9.0

Fixed via major-scoped npm overrides; package-lock.json regenerated. Build-time transitive deps.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CVE-2026-59869 fixes the 4.x line at 4.3.0 as well as 3.15.0 for 3.x. The initial commit only pinned v3; js-yaml 4.1.1 was still present and flagged. Added a major-scoped js-yaml@4 -> 4.3.0 override and regenerated the lockfile(s).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@mcollins-ttd
mcollins-ttd merged commit a696a5b into main Jul 22, 2026
2 checks passed
@mcollins-ttd
mcollins-ttd deleted the mkc-UID2-7539-vuln-npm-bumps branch July 22, 2026 05:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants