Skip to content

fix(snyk): patch high-severity js-yaml and tar vulnerabilities - #300

Merged
sree-vardhan-reddy-D merged 2 commits into
mainfrom
fix/security-vuln-js-yaml-tar
Jul 23, 2026
Merged

fix(snyk): patch high-severity js-yaml and tar vulnerabilities#300
sree-vardhan-reddy-D merged 2 commits into
mainfrom
fix/security-vuln-js-yaml-tar

Conversation

@sree-vardhan-reddy-D

@sree-vardhan-reddy-D sree-vardhan-reddy-D commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bump tar override from 7.5.13 → 7.5.19 (first version outside vulnerable range <=7.5.18)
  • Add scoped js-yaml overrides for verdaccio and @verdaccio/config to force 4.3.0 (outside vulnerable range 4.0.0–4.2.0)

DevRev

Resolves: ISS-346244 (SNYK-JS-JSYAML-17900054)
Resolves: ISS-346245 (SNYK-JS-TAR-17909068)
Resolves: ISS-346246 (SNYK-JS-TAR-17909152)

work-item: https://app.devrev.ai/devrev/issue/SURFF-1345

Test plan

  • npm audit shows zero findings for js-yaml and tar
  • npx nx test meerkat-core — 57 suites, 562 tests passed
  • npx nx test meerkat-node — 56 suites, 905 tests passed
  • npx nx build meerkat-core — clean
  • Lockfile has no js-yaml 4.0.0–4.2.0 or tar <=7.5.18 entries
  • CI passes

shriram-devrev
shriram-devrev previously approved these changes Jul 23, 2026
zaidjan-devrev
zaidjan-devrev previously approved these changes Jul 23, 2026
@shriram-devrev
shriram-devrev dismissed stale reviews from zaidjan-devrev and themself via 4d60348 July 23, 2026 08:09
@sree-vardhan-reddy-D
sree-vardhan-reddy-D force-pushed the fix/security-vuln-js-yaml-tar branch from 4d60348 to 7f2509f Compare July 23, 2026 08:25
@sree-vardhan-reddy-D
sree-vardhan-reddy-D merged commit daf1498 into main Jul 23, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants