Skip to content

fix(dep): Update to weval@0.5.0 and @bytecodealliance/jco@1.17.9 - #1601

Merged
zkat merged 2 commits into
mainfrom
kats/weval-dep-update
Oct 9, 2026
Merged

zkat merged 2 commits into
mainfrom
kats/weval-dep-update

Conversation

@harmony7

@harmony7 harmony7 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

This PR updates the @bytecodealliance/weval dependency to 0.5.0. The fix npm audit suggests is a downgrade to 3.22.4 (from before weval was added), so users have no good way to clear the finding on their side.

Before this PR, @fastly/js-compute depends on @bytecodealliance/weval, which depends on decompress@4.2.1. decompress is unmaintained and has a critical advisory, GHSA-mp2f-45pm-3cg9 / CVE-2026-53486 (archive extraction can write files and links outside the target directory). Every project that depends on @fastly/js-compute gets a critical finding from npm audit.

weval fixed this upstream in bytecodealliance/weval#32, which replaces decompress with tar + fflate. The fix shipped in weval v0.5.0 (2026-09-10) and closed bytecodealliance/weval#29.

Before this PR:

12 vulnerabilities (3 moderate, 8 high, 1 critical)

After this PR:

10 vulnerabilities (2 moderate, 8 high)

@bytecodealliance/jco@1.7.0 has the same problem and is fixed in 1.16 and later. package-lock.json had already brought in ^1.17.9, so this PR just updates the requirement as listed in package.json.

Impact

decompress is only used by weval's getWeval(). That runs when the CLI first does an AOT compilation, which is now the default in 4.0.0. It unpacks the weval binary downloaded from the bytecodealliance/weval GitHub releases into node_modules. It runs on the developer's machine or in CI, not inside the Compute sandbox. Exploiting the advisory would need a malicious archive to be served at that download URL, so the practical risk is low. The audit finding is still critical, and it affects every downstream project.

@harmony7
harmony7 requested review from TartanLlama and zkat October 9, 2026 04:52
@harmony7
harmony7 force-pushed the kats/weval-dep-update branch from 007a342 to 922c472 Compare October 9, 2026 05:53
@harmony7 harmony7 changed the title fix(dep): Update to eval@0.5.0 fix(dep): Update to eval@0.5.0 and @bytecodealliance/jco@1.17.9 Oct 9, 2026
@zkat zkat changed the title fix(dep): Update to eval@0.5.0 and @bytecodealliance/jco@1.17.9 fix(dep): Update to weval@0.5.0 and @bytecodealliance/jco@1.17.9 Oct 9, 2026
Removed fixed section and related entry from changelog.
@zkat
zkat enabled auto-merge (squash) October 9, 2026 16:04
@zkat
zkat merged commit 769f43b into main Oct 9, 2026
29 checks passed
@zkat
zkat deleted the kats/weval-dep-update branch October 9, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: transitive decompress is unmaintained and vulnerable (GHSA-mp2f-45pm-3cg9 / CVE-2026-53486, CVSS 9.1)

2 participants