Skip to content

Fix CVEs: postcss, js-yaml, tar, axios, shell-quote, brace-expansion, undici - #400

Merged
mraible merged 2 commits into
mainfrom
fix/cve-july-2026
Aug 11, 2026
Merged

Fix CVEs: postcss, js-yaml, tar, axios, shell-quote, brace-expansion, undici#400
mraible merged 2 commits into
mainfrom
fix/cve-july-2026

Conversation

@mraible

@mraible mraible commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates yarn resolutions to resolve security vulnerabilities in transitive dependencies:

  • postcss 8.5.14 → 8.5.18
  • js-yaml 4.2.0 → 4.3.0 (prototype pollution)
  • tar 7.5.16 → 7.5.21 (path traversal)
  • axios 1.16.0 → 1.18.1 (multiple CVEs)
  • shell-quote 1.8.4 → 1.9.0
  • brace-expansion 5.0.6 → 5.0.9 (ReDoS)
  • undici → 6.28.0 (added, multiple CVEs)

Note: nx CVEs (require major version bump 21→22) are not addressed in this PR and should be handled separately.

…ell-quote 1.9.0, brace-expansion 5.0.9, undici 6.28.0
@mraible
mraible requested a review from a team August 10, 2026 16:33
@mraible
mraible enabled auto-merge (squash) August 10, 2026 17:15
@mraible
mraible merged commit a5d7978 into main Aug 11, 2026
6 checks passed
@mraible
mraible deleted the fix/cve-july-2026 branch August 11, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants