From d21a12ee4beedff64c0413edb59a757e391e7534 Mon Sep 17 00:00:00 2001 From: Matteo Date: Fri, 2 Oct 2026 18:18:04 +0200 Subject: [PATCH] Revert js-yaml 5 (#809): the image no longer booted The runtime image copies only the hoisted node_modules of the prod-deps stage, not packages/backend/node_modules. js-yaml 5 was the backend's first nested dependency (the root keeps 4.3.2 for other packages), so the backend loaded 4.3.2 at runtime and crashed on CORE_SCHEMA.withTags. Unit tests resolve the nested copy and passed; only the post-merge Docker boot check caught it. Nothing was published. Back to js-yaml 4.3.2 (not in the advisory's 5.0.0-5.4.0 range). The YAML merge-key regression test stays: it passes on 4.x as well. --- package-lock.json | 24 +------------------ packages/backend/package.json | 2 +- .../src/connectors/parsers/openapi.parser.ts | 10 ++------ 3 files changed, 4 insertions(+), 32 deletions(-) diff --git a/package-lock.json b/package-lock.json index ca9bd433..882ea853 100644 --- a/package-lock.json +++ b/package-lock.json @@ -24593,7 +24593,7 @@ "helmet": "^8.3.0", "https-proxy-agent": "^7.0.6", "ioredis": "^5.11.1", - "js-yaml": "^5.4.1", + "js-yaml": "^4.3.2", "mongodb": "^7.6.0", "mssql": "^12.7.2", "mysql2": "^3.24.4", @@ -24814,28 +24814,6 @@ "url": "https://github.com/sponsors/epoberezkin" } }, - "packages/backend/node_modules/js-yaml": { - "version": "5.4.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.1.tgz", - "integrity": "sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==", - "funding": [ - { - "type": "github", - "url": "https://github.com/sponsors/puzrin" - }, - { - "type": "github", - "url": "https://github.com/sponsors/nodeca" - } - ], - "license": "MIT", - "dependencies": { - "argparse": "^2.0.1" - }, - "bin": { - "js-yaml": "bin/js-yaml.mjs" - } - }, "packages/backend/node_modules/json-schema-traverse": { "version": "1.0.0", "resolved": "https://registry.npmjs.org/json-schema-traverse/-/json-schema-traverse-1.0.0.tgz", diff --git a/packages/backend/package.json b/packages/backend/package.json index 83cfabd8..acc2893c 100644 --- a/packages/backend/package.json +++ b/packages/backend/package.json @@ -62,7 +62,7 @@ "helmet": "^8.3.0", "https-proxy-agent": "^7.0.6", "ioredis": "^5.11.1", - "js-yaml": "^5.4.1", + "js-yaml": "^4.3.2", "mongodb": "^7.6.0", "mssql": "^12.7.2", "mysql2": "^3.24.4", diff --git a/packages/backend/src/connectors/parsers/openapi.parser.ts b/packages/backend/src/connectors/parsers/openapi.parser.ts index 2608e801..9b52c144 100644 --- a/packages/backend/src/connectors/parsers/openapi.parser.ts +++ b/packages/backend/src/connectors/parsers/openapi.parser.ts @@ -4,16 +4,10 @@ import { capToolName } from './tool-name.util'; const SwaggerParser = require('swagger-parser'); import axios from 'axios'; -import { CORE_SCHEMA, load as loadYaml, mergeTag, timestampTag } from 'js-yaml'; +const yaml = require('js-yaml') as { load: (s: string) => unknown }; import { assertSafeOutboundUrl } from '../../common/ssrf.util'; import { normalizeOpenApi31 } from './openapi-3.1-normalizer'; -// js-yaml 5 loads with the bare YAML 1.2 core schema. Real-world specs use -// `<<: *anchor` merge keys, which it would keep as a literal "<<" property, -// so add merge (and timestamps) back: the same result js-yaml 4 gave. Not -// YAML11_SCHEMA: its 1.1 booleans turn a property named `y` or `on` into `true`. -const SPEC_YAML_SCHEMA = CORE_SCHEMA.withTags(mergeTag, timestampTag); - export interface ParsedTool { name: string; /** @@ -175,7 +169,7 @@ export class OpenApiParser { return JSON.parse(input); } try { - return loadYaml(input, { schema: SPEC_YAML_SCHEMA }); + return yaml.load(input); } catch (yamlErr) { // Last-resort: try JSON anyway so the original error surfaces if the // input is genuinely malformed.