Skip to content

chore: upgrade js-yaml to ^4.3.0 to address CVE-2026-59869#1470

Open
linear-code[bot] wants to merge 2 commits into
mainfrom
linear/sou-1551-sourcebot-devsourcebot-cve-2026-59869-js-yaml-js-yaml-5e0b
Open

chore: upgrade js-yaml to ^4.3.0 to address CVE-2026-59869#1470
linear-code[bot] wants to merge 2 commits into
mainfrom
linear/sou-1551-sourcebot-devsourcebot-cve-2026-59869-js-yaml-js-yaml-5e0b

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1551

Addresses CVE-2026-59869 (HIGH): js-yaml can spend quadratic CPU time parsing crafted YAML documents that chain merge keys, enabling a denial of service. Fixed in js-yaml 4.3.0.

All requesters (@apidevtools/json-schema-ref-parser, @eslint/eslintrc, json-schema-to-typescript) already declared ^4.1.x ranges that admit 4.3.0, so this is a lockfile refresh only (yarn up -R js-yaml) — no package.json or resolutions change needed. yarn why js-yaml confirms every instance now resolves to 4.3.0.


Note

Low Risk
Patch-level transitive dependency update with no application code changes; typical low-risk security maintenance.

Overview
Security dependency bump for transitive js-yaml: the lockfile now resolves js-yaml@^4.1.1 to 4.3.0 (from 4.2.0), with no package.json or resolutions edits because existing ^4.1.x ranges already allow 4.3.0.

This addresses CVE-2026-59869, where parsing crafted YAML with chained merge keys could cause quadratic CPU use (DoS). The [Unreleased] changelog records the upgrade under Fixed.

Reviewed by Cursor Bugbot for commit 34dfd2a. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

@brendan-kellam
brendan-kellam marked this pull request as ready for review July 21, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants