Skip to content

UID2-7538/7539/7540/7541: bump axios, brace-expansion, js-yaml, shell-quote across web-integrations examples#201

Merged
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7538-vuln-npm-bumps
Jul 22, 2026
Merged

UID2-7538/7539/7540/7541: bump axios, brace-expansion, js-yaml, shell-quote across web-integrations examples#201
mcollins-ttd merged 2 commits into
mainfrom
mkc-UID2-7538-vuln-npm-bumps

Conversation

@mcollins-ttd

Copy link
Copy Markdown
Contributor

Fixes HIGH trivy findings across the 7 web-integrations example sub-projects via per-project major-scoped npm overrides + lockfile regen.

CVE/GHSA Package Fix Jira
GHSA-gcfj-64vw-6mp9 axios →>=1.18.0 UID2-7538
CVE-2026-13149 brace-expansion v5→5.0.7 UID2-7539
CVE-2026-59869 js-yaml v3→3.15.0 UID2-7540
CVE-2026-13311 shell-quote v1→1.9.0 UID2-7541

All 7 affected package-lock.json files regenerated; no vulnerable versions remain.

mcollins-ttd and others added 2 commits July 22, 2026 01:45
…-quote across web-integrations examples (trivy HIGH CVEs)

- GHSA-gcfj-64vw-6mp9: axios -> >=1.18.0
- CVE-2026-13149: brace-expansion v5 -> 5.0.7
- CVE-2026-59869: js-yaml v3 -> 3.15.0
- CVE-2026-13311: shell-quote v1 -> 1.9.0

Applied per sub-project (7 lockfiles) via major-scoped npm overrides; all package-lock.json regenerated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CVE-2026-59869 fixes the 4.x line at 4.3.0 as well as 3.15.0 for 3.x. The initial commit only pinned v3; js-yaml 4.1.1 was still present and flagged. Added a major-scoped js-yaml@4 -> 4.3.0 override and regenerated the lockfile(s).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@mcollins-ttd
mcollins-ttd merged commit a08b24c into main Jul 22, 2026
3 checks passed
@mcollins-ttd
mcollins-ttd deleted the mkc-UID2-7538-vuln-npm-bumps branch July 22, 2026 05:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants