chore(deps): update dependency style-dictionary to v5.4.4 [security] - #440
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency style-dictionary to v5.4.4 [security]#440renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.0.1→5.4.4Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-54639 / GHSA-vj5c-m527-mpff
More information
Details
Impact
Prototype pollution.
A malicious user can create a token array
[{ key: '{__proto__.foo}', value: 'malicious' }], when processed byconvertTokenData()utility function, it will pollute the Object.prototype globally where{}.foowill equal{ key: '{__proto__.foo}', value: 'malicious' }.This has been confirmed with a test/reproduction.
You are impacted when:
convertTokenData(tokens, { output: 'object' });sd.tokensproperty with thesd.tokenMapproperty by converting tokenData map back to object.sd.tokensproperty with thesd.tokenMapproperty.Impact is high for this when style-dictionary is used as an integration in a NodeJS server application.
Impact is moderate for when style-dictionary is used as an integration in a Web application.
Impact is low for most common cases where the user of style-dictionary also maintains the tokens, and access is limited via read/write access to the repository/workflows where it is used.
Patches
A patch has been published: version
5.4.4.Any version within range
>=4.3.0 <5.4.4contains this vulnerability, see commit hash 209085d for when the vulnerability was added.See PR with repro + fix https://github.com/style-dictionary/style-dictionary/pull/1702
Workarounds
A workaround is to sanitize your token data first. Whether using DTCG format or old Style Dictionary format, you have to check the token data object recursively for any object keys that include
__proto__.You can do this with the StyleDictionary instance too, just ensure that expand has to be set to false to prevent the second method of this vulnerability from happening.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
style-dictionary/style-dictionary (style-dictionary)
v5.4.4Compare Source
Patch Changes
23b5e8d: Fix prototype pollution vulnerability in theconvertTokenDatautility function, this was introduced in version4.3.0.Any token key that includes
__proto__will be ignored.See Security Advisory GHSA-vj5c-m527-mpff.
v5.4.3Compare Source
Patch Changes
371dbcb: Get proper deepmerge types in, fix small potential bug forStyleDictionary.extend(), flagged by type safety improvement.v5.4.2Compare Source
Patch Changes
60d16e1: Fix sizeRem and sizePxToRem transform to keep the 0-valued tokens type number/string intact in the result (regression 5.4.0)v5.4.1Compare Source
Patch Changes
46ec860: Fixsize/remtransform stripping the unit from zero-magnitude dimension values (e.g."0em"), which caused downstream CSS variables to serialize asundefined. Unit preservation now runs before the unitless-zero short-circuit.v5.4.0Compare Source
Minor Changes
edceda7: Add support for DTCG v2025.10 dimension token type object value, while remaining backwards compatible for dimension tokens using string values.All built-in transforms can now handle dimension tokens.
This includes CSS shorthand transforms for composed token types such as typography, border and shadows, which can contain properties that are dimensions.
{ "spacing": { "$type": "dimension", "$value": { "value": 1, "unit": "px" } }, "shadow": { "$type": "shadow", "$value": { "color": { "colorSpace": "srgb", "components": [0, 0, 0], "alpha": 0.4 }, "offsetX": { "value": 2, "unit": "px" }, "offsetY": { "value": 2, "unit": "px" }, "blur": { "value": 4, "unit": "px" }, "spread": { "value": 6, "unit": "px" } } } }3d5c140: Generate strict types (tuples) for the tokens of the same typePatch Changes
edceda7: Fix very old bug where size/remToPt wasn't converting toptunit, but rather tof(iOS float). Fixed this, addedsize/remToFloatto use the old behavior, and updated the ios transformGroup to use this instead. This is technically potentially "breaking" but because it is a bugfix, this is a patch.v5.3.3Compare Source
Patch Changes
52817e1: Fix vulnerability in bundled version of glob -> minimatch.v5.3.2Compare Source
Patch Changes
a7986d2: Support DTCGinsetboolean property in shadow/css/shorthand transform, in addition to the existingtype: "inset"format.Don't put invalid inset values in shadow/css/shorthand box-shadow values, they are ignored now. E.g. if you put
type: "innerShadow"or some other unrecognized string.v5.3.1Compare Source
Patch Changes
9f51f0d: Fix shadow and border CSS shorthands to also support latest DTCG color module. Add platform options to configure how the shorthand transforms stringify the color property.v5.3.0Compare Source
Minor Changes
b5adbc0: Add support for DTCG v2025.10 structured color format in color transformers.New features:
colorSpace,components,alpha, and optionalhexfallback propertiessrgb,srgb-linear,display-p3,a98-rgb,prophoto-rgb,rec2020,xyz-d50,xyz-d65,lab,lch,oklab,oklch,hsl,hwbcolor/oklchtransformer - outputs modern CSSoklch()functioncolor/oklabtransformer - outputs modern CSSoklab()functioncolor/p3transformer - outputs CSScolor(display-p3 ...)functioncolor/lchtransformer - outputs modern CSSlch()functionTypes:
DTCGColorSpaceandDTCGColorValueTypeScript typesHex fallback support:
When a DTCG color object includes a
hexproperty, it will be used as a fallback when the color is out-of-gamut for sRGB, allowing designers to provide pre-computed sRGB approximations.Patch Changes
1187f60: Update vulnerable transitive lodash dependency inside @bundled-es-modules/globv5.2.0Compare Source
Minor Changes
752a50c: Add (wip) sort option to formattedVariables and formats css, scss, less, stylus. See format docs on how to use it.Patch Changes
6e9164e: Small bugfix where formatting.commentStyle was not taken into account for fileHeader comments when possible.v5.1.4Compare Source
Patch Changes
a9c11a2: Fix of a regression bug caused by sizeRem transform throwing an error for NaN values. Because a string was thrown instead of an Error, this wasn't handled correctly by the transforms wrapper utility. Now we handle this scenario, and we also changed it to throw an actual Error.v5.1.3Compare Source
Patch Changes
6e306bc: Upgrade glob@11.1.0 forked package to fix vulnerability in origin package.v5.1.1Compare Source
Patch Changes
65745da: Fix outputReferences for tokens with 'value' in their name. Previously, references to tokens likeobject_type.value_chainwere incorrectly resolved because the code removed the first occurrence of.valueinstead of only the trailing suffix.v5.1.0Compare Source
Minor Changes
97a209a: Add new size/compose/{sp,dp} transformsPatch Changes
dbcdae3: Fix fontName parsing to handle double quotesc47600d: Export expand DTCGTypesMap for extension use cases.v5.0.4Compare Source
Patch Changes
7a238af: Fix an issue with token collisions being way to eager about complaining when values that are identical are "colliding". This cuts collision warnings by 75% or more.v5.0.3Compare Source
Patch Changes
3d070f5: Move patch-package to devDependencies and run in prepare instead of postinstall, so it only runs when npm installing locally and not for consumers.71614da: Wrap structuredClone in loadFile in a try catch, in case we have a JS/TS config file with dynamic content.v5.0.2Compare Source
Patch Changes
8e413a2: Fix vulnerable dependencies, patch-package and its transitivetmpdependency in particular.9f84a81: Remove node-sass from create-react-app example, dart-sass is used now usually.da19c8f: Small patch to allow no-destination "files" to not cause errors when using clean methods.Configuration
📅 Schedule: (in timezone Europe/Prague)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.