fix(security): update dependency js-yaml to v4 [security] - abandoned - #1435
fix(security): update dependency js-yaml to v4 [security] - abandoned#1435renovate[bot] wants to merge 6 commits into
Conversation
|
✅ Deploy Preview for openfeature ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
39b7a37 to
2724ad3
Compare
|
@copilot fix the CI failures |
Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
|
@copilot can you rebase this branch, and still seeing some failures running |
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
…ation (#1416) ## This PR - Fixes grammar, spelling, and typos across the reference documentation, and corrects two broken code examples. ## Related Issues _None._ (No tracking issue — small documentation cleanup.) ## Notes - Two of the changes are genuine code-example bugs (PHP `::` static call, Python `False`), not just wording — the snippets would fail as previously written. ## Follow-up Tasks ## How to test - No functional testing needed — documentation only. - Optional: `yarn build` (Docusaurus) to confirm the MDX still compiles, and `yarn lint:md` for markdownlint. Signed-off-by: Jose Bovet Derpich <jose.bovet@gmail.com> Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>
The PR was automatically generated via the update-sdk-docs GitHub workflow. Signed-off-by: OpenFeature Bot <109696520+openfeaturebot@users.noreply.github.com> Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>
- Resolved 8 open Dependabot security alerts by bumping transitive dependency resolutions in `package.json` - 3 alerts (image-size x2, tsup) have no patched version available upstream yet and are left unresolved | Alert | Package | Severity | Fix | |-------|---------|----------|-----| | #287 | `nanoid` | **high** | Bumped to 3.3.17 via resolution | | #285 | `js-yaml` (3.x) | **high** | Bumped to 3.15.1 via `gray-matter/js-yaml` resolution | | #284 | `js-yaml` (4.x) | **high** | Bumped to 4.3.1 via `markdownlint-cli2/js-yaml`, `js-yaml@npm:^4.1.0`, `@redocly/openapi-core/js-yaml`, `cosmiconfig/js-yaml` resolutions | | #283 | `mermaid` | **medium** | Bumped to 11.16.1 via `@docusaurus/theme-mermaid/mermaid` resolution | | #281 | `mermaid` | low | Bumped to 11.16.1 (same fix as above) | | #279 | `mermaid` | **medium** | Bumped to 11.16.1 (same fix as above) | | #277 | `mermaid` | **medium** | Bumped to 11.16.1 (same fix as above) | | #275 | `mermaid` | **medium** | Bumped to 11.16.1 (same fix as above) | - #289 `image-size` <= 2.0.2 (high) — ICNS parser DoS - #288 `image-size` <= 2.0.2 (high) — JXL/HEIF parser DoS - #80 `tsup` <= 8.3.4 (low) — DOM Clobbering - [x] `yarn install` regenerates lockfile with patched versions for all fixed packages - [x] `yarn build` succeeds - [x] `yarn typecheck` produces only pre-existing, unrelated errors (verified identical on unmodified main) - [x] `yarn run lint:md` passes Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com> Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>
Co-authored-by: jonathannorris <1219069+jonathannorris@users.noreply.github.com>
Done in commit 6077e24. I rebased the branch onto the latest main changes and fixed |
This PR contains the following updates:
^3.15.0→^4.0.0JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-5p4m-2wfm-xmqj
More information
Details
Quadratic CPU consumption in
!!omapresolution (js-yaml 3.x and 4.x)Summary
resolveYamlOmap()enforces key uniqueness for!!omapsequences with a linearscan (
objectKeys.indexOf(...)) inside the per-element loop, making resolutionO(n²) in the number of entries. A modestly sized YAML document therefore
consumes disproportionate CPU inside
yaml.load(), giving a denial of serviceagainst any consumer that parses untrusted YAML.
!!omapis registered in the default schema(
lib/schema/default.js→require('../type/omap')), so a plainyaml.load(untrustedInput)with no options is affected — no custom schema ornon-default configuration is required.
This is the same weakness as CVE-2026-59870 / GHSA-724g-mxrg-4qvm, which was
fixed in the 5.x line in 5.2.1. That fix was never backported: both currently
maintained legacy lines still carry the original implementation.
Affected versions
objectKeys.indexOf(pairKey)atlib/type/omap.js:29objectKeys.indexOf(pairKey)atlib/type/omap.js:30Set)Both figures are the newest release of each line at the time of writing, so
this is not a "you are on an old version" issue.
Details
lib/type/omap.js(js-yaml 4.3.0):objectKeysgrows by one element per entry, andArray.prototype.indexOfis alinear scan, so resolving an
n-entry!!omapperforms roughly1 + 2 + … + ncomparisons — quadratic inn. The work happens synchronouslyinside
yaml.load(), blocking the event loop for its whole duration.The 5.x line already solves exactly this by tracking seen keys in a
Set(
src/tag/sequence/omap.ts):Proof of concept
Measured (node v20.20.2, default heap, no flags)
js-yaml 4.3.0
js-yaml 3.15.0
Runtime grows by a factor of ~4 for each doubling of
n, which is thesignature of O(n²) (linear growth would be ~2×).
Scaling further: a 2.48 MB document with 150,000 entries blocked
yaml.load()for 10.8 seconds.Impact
Any service that parses attacker-influenced YAML with js-yaml 3.x or 4.x can be
stalled with a small input. Because the loop is synchronous, a single request
blocks the Node.js event loop and stalls every other request in the process —
so the amplification is per-process, not just per-request.
Suggested severity: consistent with CVE-2026-59870 (the same weakness in
5.x), i.e. Availability-only impact, network attack vector, no privileges or
user interaction required.
Suggested fix
Mirror the 5.x fix — replace the linear scan with a
Set:This preserves the existing duplicate-key rejection semantics exactly while
making resolution O(n). A
maxOmapLength-style cap would also work, but theSetmatches what 5.x already ships and requires no new option.References
lib/type/omap.js(3.x, 4.x) — the affected resolverlib/schema/default.js— registers!!omapin the default schemaDiscovery
Found by an automated static-analysis and executed-proof-of-concept scanner run
against js-yaml 4.2.0, then manually verified against 3.15.0 and 4.3.0 by
executing the proof of concept above. All timings in this report were measured
on the current releases of each line, not on the version originally scanned.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodeca/js-yaml (js-yaml)
v4.3.1Compare Source
v4.3.0Compare Source
v4.2.0Compare Source
Added
docs/safety.mdwith notes about processing untrusted YAML.maxDepth(100) loader option. Not a problem, but gives a betterexception instead of RangeError on stack overflow.
maxMergeSeqLength(20) loader option. Not a problem aftermergefix,but an additional restriction for safety.
dist/builds.Changed
dist/files are no longer kept in the repository.Fixed
Security
elements (makes sense for malformed files > 10K).
v4.1.1Compare Source
Security
v4.1.0Compare Source
Added
yaml.types.XXX.optionsproperty with original arguments kept as they were(see
yaml.types.int.optionsas an example).Changed
Schema.extend()now keeps old type order in case of conflicts(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as
abcdinstead ofcbad).v4.0.0Compare Source
Changed
!!js/function,!!js/regexp,!!js/undefinedaremoved to js-yaml-js-types package.
safe*functions. Useload,loadAll,dumpinstead which are all now safe by default.
yaml.DEFAULT_SAFE_SCHEMAandyaml.DEFAULT_FULL_SCHEMAare removed, useyaml.DEFAULT_SCHEMAinstead.yaml.Schema.create(schema, tags)is removed, useschema.extend(tags)instead.!!binarynow always mapped toUint8Arrayon load./libfolder.01234is now decimal,0o1234is octal,1:23is parsed as string instead of base60).dump()no longer quotes:,[,],(,)except when necessary, #470, #557.(X:Y)instead ofat line X, column Y(also present in compact format), #332.dump()now serializesundefinedasnullin collections and removes keys withundefinedin mappings, #571.dump()withskipInvalid=truenow serializes invalid items in collections as null.!are now dumped as!taginstead of!<!tag>, #576.tag:yaml.org,2002:are now shorthanded using!!, #258.Added
.mjs(es modules) support.quotingTypeandforceQuotesoptions for dumper to configurestring literal style, #290, #529.
styles: { '!!null': 'empty' }option for dumper(serializes
{ foo: null }as "foo:"), #570.replaceroption (similar to option in JSON.stringify), #339.Tagcan now handle all tags or multiple tags with the same prefix, #385.Fixed
dump(), #587.[foo,,bar]) now throw an exceptioninstead of producing null, #321.
__proto__key no longer overrides object prototype, #164.bower.json.load()and url-encoded indump()(previously usage of custom non-ascii tags may have led to invalid YAML that can't be parsed).
v3.15.1Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.