Skip to content

Chore(deps): js-yaml 3.15.2 / 4.3.2 and svgo 3.3.5 (today's advisories) - #753

Merged
adibhanna merged 1 commit into
mainfrom
chore/js-yaml-svgo-advisories
Sep 8, 2026
Merged

adibhanna merged 1 commit into
mainfrom
chore/js-yaml-svgo-advisories

Conversation

@adibhanna

Copy link
Copy Markdown
Contributor

Lockfile-only bump for three advisories published today that turn the production audit red, here and in the phone shells, which audit this checkout at their pin.

Every move stays inside the dependents' existing ranges, so package.json is untouched. hono's moderate advisories remain, below the gate.

Verification

  • npm audit --omit=dev --audit-level=high exits 0 (one moderate left).
  • npm run typecheck: 7/7 tasks.

The iOS and Android shells re-pin to the squash commit once this lands.

Lockfile-only. Three advisories published today turn the production
audit red: js-yaml GHSA-2883-xcg3-v3hh (3.15.1 -> 3.15.2 for
gray-matter's copy, 4.3.1 -> 4.3.2 for the root copy) and svgo
GHSA-w27v-7q3p-w38r / GHSA-4vpr-x523-8j87 (3.3.4 -> 3.3.5, reached
through node-tikzjax in the desktop app). Every move stays inside the
dependents' existing ranges, so package.json is untouched. hono's
moderate advisories remain, below the gate.
@adibhanna
adibhanna merged commit a3e638f into main Sep 8, 2026
7 checks passed
@adibhanna
adibhanna deleted the chore/js-yaml-svgo-advisories branch September 8, 2026 23:04
adibhanna added a commit to ZenNotes/zennotesandroid that referenced this pull request Sep 8, 2026
The pin moves from the v2.46.0 tag commit to the upstream main commit
that bumps js-yaml and svgo in its lockfile (ZenNotes/zennotes#753), so
CI's audit of the upstream checkout passes again. The app core stays
2.46.0: the two commits past the tag are packaging metadata and that
lockfile. No shell changes.
adibhanna added a commit to ZenNotes/zennotesios that referenced this pull request Sep 8, 2026
The pin moves from 3301a29 (one past v2.45.0) to the upstream main
commit that bumps js-yaml and svgo in its lockfile
(ZenNotes/zennotes#753), so CI's audit of the upstream checkout passes
again. That takes main's app core to 2.46.0 plus the packaging-metadata
and lockfile commits behind it. No shell changes: the 2.45 -> 2.46
bridge-contract diff is optional fields only (kanbanFolderRoot, comment
author/parentId, supportsCustomTemplates, the 'templates' change kind),
and the desktop vault.ts change moves comment normalization out of a
file this shell keeps its own copy of. release/1.9.8 still pins the
v2.46.0 tag commit and needs the same move before its PR can go green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant