fix(deps): clear the js-yaml advisory from the Electron chain (R-10) - #47
Merged
Merged
Conversation
GHSA-2883-xcg3-v3hh (high, CVSS 7.5) reached the Electron app's production tree through electron-updater 6.8.9 -> js-yaml 4.3.1, the update-check chain. It was the last high advisory in a shipped production tree and the only record still carried as an accepted residual. Lockfile-only fix: `npm update js-yaml --package-lock-only --ignore-scripts` moved js-yaml 4.3.1 -> 4.3.2, inside both electron-updater's declared ^4.1.0 and the existing ^4.2.0 override in electron/package.json. No package.json change and no new override were needed. node_modules was not touched. electron prod before: high 1, total 1 -> after: 0 across every severity electron full after: 0 across every severity (the dev-only app-builder-lib / builder-util / dmg-builder copies dedupe onto the same hoisted entry, so one bump cleared them too) root prod 0 before and after - untouched by this change The lockfile diff is five lines: three for js-yaml (version, resolved, integrity) and two where npm synchronised the lockfile's own version field from a stale 3.8.51 to the 3.8.54 already declared in electron/package.json. No other package changed version. Docs updated to match: R-10 is marked fixed in the vulnerability register (summary row, detail section, proposed-PR item) with a new Electron re-measurement section, and EVOLUTION_STATUS's Phase 10 table, risks table and known-limits list no longer describe it as an accepted residual. Verified: check:lockfile OK; both commands behind audit:electron exit 0; check-doc-links, check-fabricated-docs, check-docs-frontmatter, check-docs-sync and check-changelog-integrity all pass. A full electron-builder packaging run was not executed - it needs the Electron binaries and a signing environment this worktree does not have; the packaging config was verified to parse and to be unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Items 1 and 2 of that section are both applied now — adm-zip 0.6.1 in PR #42 and js-yaml 4.3.2 in this one — so a heading reading "Proposed dependency PR (not applied)" states the opposite of what the section records. Renaming it moves the anchor, which is why it was left alone. But all three references live inside this same file, so there was nothing external to break: the heading and its three links are updated together. check-doc-links exit 0 — 172 docs, 1044 internal links, none broken Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This was referenced Sep 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Clears R-10 —
GHSA-2883-xcg3-v3hh(high, CVSS 7.5, CWE-400/CWE-407) — from the Electron app's production dependency tree.It was the last high advisory in a shipped production tree, and the only record still carried as an accepted residual.
Dependency chain
The dev-only
electron-builderpackages (app-builder-lib,builder-util,dmg-builder26.15.3) dedupe onto the same hoisted copy, so a single bump cleared both trees.Blast radius is the Electron shell's update-check chain only (
electron/main.jsloadselectron-updaterand callsautoUpdater.checkForUpdates(), which parses release-metadata YAML from the GitHub publish feed). Not in the container image, the npm package or the server runtime.The fix
Lockfile-only:
js-yaml4.3.1 → 4.3.2 (thev4-legacydist-tag; first fixed version per the advisory).electron/package.jsonis unchanged. The existing^4.2.0override already permitted 4.3.2, so no newoverridesentry was needed.node_moduleswas not touched — other worktrees share it.Before / after
npm audit --omit=dev --package-lock-only:The Electron tree is also clean in the full run including dev deps (
npm audit --package-lock-only):{"info":0,"low":0,"moderate":0,"high":0,"critical":0,"total":0}.Root production was already at zero (PR #42's
adm-zipfix) and is untouched here.Nothing unrelated moved
Three of those lines are
js-yaml(version,resolved,integrity). The other two are npm synchronising the lockfile's ownversionfield from a stale3.8.51to the3.8.54already declared inelectron/package.json— a pre-existing drift, not a dependency change. No other package changed version.Verification actually run
npm run check:lockfile— OK (no issues; workspace lock entries match their manifests)npm --prefix electron audit --audit-level=critical— exit 0npm --prefix electron audit --audit-level=high— exit 0 (the non-blocking high-severity warningaudit:electronused to print is gone)check-doc-links— PASS, 172 docs / 1044 internal linkscheck-fabricated-docs— PASS, no fabricated referencescheck-docs-frontmatter— OK, 132 docscheck-docs-sync— PASScheck-changelog-integrity— OK, no base bullets lostStated plainly, not claimed
electron-builderpackaging run was NOT executed. It needs a download of the Electron binaries and a signing environment this worktree does not have. What was checked:electron/package.jsonparses, itsbuildblock is unchanged by this commit, and the only file touched underelectron/ispackage-lock.json.audit:electronscript was not run end to end on this machine — its(cmd || echo)POSIX shell form is rejected by cmd.exe before npm audit runs. That is a pre-existing Windows-only limitation of the script, unrelated to this change; the two commands behind it were run directly and both exit 0.Docs
docs/security/VULNERABILITY_REGISTER.md— R-10 marked Fixed in the summary row, detail section and proposed-PR item; new "Electron re-measurement — 2026-09-19" section; the stale "1 high advisory … (R-10)" and "Electron app lockfile is unchanged" sentences corrected.docs/EVOLUTION_STATUS.md— Phase 10 supply-chain table re-measured (Electron productionhigh: 1→0), the "accepted as residual" paragraph rewritten, the Risks row marked Closed, and the known-limits bullet struck through.R-10 is closed. No advisory is accepted as residual in either shipped production tree.
🤖 Generated with Claude Code