Skip to content

fix(FFESUPPORT-884): remediate July 2026 dependabot vulnerabilities - #285

Merged
aarsilv merged 1 commit into
mainfrom
aarsilv/ffesupport-884/fix-vulnerabilities
Jul 20, 2026
Merged

aarsilv merged 1 commit into
mainfrom
aarsilv/ffesupport-884/fix-vulnerabilities

Conversation

@aarsilv

@aarsilv aarsilv commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

Remediates the 4 open Dependabot alerts in js-client-sdk — all dev-only transitive dependencies. Jira: https://datadoghq.atlassian.net/browse/FFESUPPORT-884

Advisories closed

Advisory Severity Package Before → After Pulled via
ws DoS (GHSA) high ws 8.20.0 → 8.21.1 jest-environment-jsdom → jsdom
GHSA-h67p-54hq-rp68 medium js-yaml 3.14.2 → 3.15.0 jest → @istanbuljs/load-nyc-config
GHSA-h67p-54hq-rp68 medium js-yaml 4.1.1 → 4.3.0 eslint@8 + @microsoft/api-documenter
GHSA-4x5r-pxfx-6jf8 low @babel/core 7.29.0 → 7.29.7 jest / ts-jest

Approach

Lockfile-only re-resolution to patched in-range versions, plus one scoped resolution ("@microsoft/api-documenter/js-yaml": "^4.2.0"): api-documenter pins js-yaml ~4.1.0 (capped at the vulnerable 4.1.x, no upstream fix even at latest), and it's a dev-only doc-gen tool where js-yaml 4.x is API-stable. No runtime/prod dependency moved.

How the tests/CI protect this change

  • yarn install --frozen-lockfile ✓; yarn typecheck ✓; eslint '**/*.ts' ✓.
  • yarn test:unit — 153 tests / 11 suites pass (jsdom uses ws; jest uses @babel/core; api-documenter uses js-yaml).
  • CI runs across the Node 20/22/24 matrix.

Deferred advisories

None — all 4 alerts addressed; none left dismissed/auto-dismissed.

Re-resolve dev-only transitive deps to patched, in-range versions:
- ws 8.20.0 -> 8.21.1 (GHSA ws DoS, via jest-environment-jsdom -> jsdom)
- js-yaml 3.14.2 -> 3.15.0 (GHSA-h67p-54hq-rp68, via jest/istanbul)
- js-yaml 4.1.1  -> 4.3.0  (GHSA-h67p-54hq-rp68, via eslint + api-documenter)
- @babel/core 7.29.0 -> 7.29.7 (GHSA-4x5r-pxfx-6jf8, via jest)

@microsoft/api-documenter pins js-yaml ~4.1.0 (capped at vulnerable 4.1.x)
even at latest, so a scoped resolution forces that one path to ^4.2.0.
Dev-only tooling; no runtime dependency moved.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repo’s Yarn lockfile to remediate July 2026 Dependabot vulnerability alerts affecting dev-only transitive dependencies, and adds a targeted Yarn resolution to unblock a patched js-yaml 4.x for @microsoft/api-documenter.

Changes:

  • Bumps vulnerable transitive packages in yarn.lock to patched versions (notably ws, js-yaml, @babel/core and related Babel packages).
  • Adds a scoped Yarn resolutions entry to force @microsoft/api-documenter’s js-yaml dependency to a non-vulnerable 4.x version.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
yarn.lock Re-resolves dev transitive dependency graph to patched versions (e.g., ws@8.21.1, js-yaml@3.15.0/4.3.0, @babel/core@7.29.7).
package.json Adds a targeted Yarn resolutions override for @microsoft/api-documenter/js-yaml to allow a patched js-yaml 4.x.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@aarsilv

aarsilv commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Response from codex:

LGTM

  • yarn.lock resolves ws 8.21.1, js-yaml 3.15.0/4.3.0, and @babel/core 7.29.7; none of the cited vulnerable versions remain.
  • package.json changes only the scoped @microsoft/api-documenter/js-yaml resolution; production dependencies are untouched.
  • The forced js-yaml 4.3.0 exceeds API Documenter’s ~4.1.0 range, but risk is limited to dev-only documentation tooling and remains within major version 4.
  • No advisory is deferred: the API Documenter pin is actively overridden, and the diff contains only package.json/yarn.lock remediation changes.

(codex ran locally via codex exec read-only; relayed here — GitHub blocked codex posting directly under the sandbox.)

@aarsilv
aarsilv merged commit e6b3b8f into main Jul 20, 2026
8 checks passed
@aarsilv
aarsilv deleted the aarsilv/ffesupport-884/fix-vulnerabilities branch July 20, 2026 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants