[sec-check] fix: bump discord js-yaml 4.3.1 → 4.3.2 (GHSA-2883-xcg3-v3hh) - #6336
Conversation
|
Changelog: this PR changes code but carries no changelog entry If it is user-visible — a feature, a fix an operator would notice, a This is a reminder, not a gate; it never blocks a merge. |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Thank you for your contribution! Your PR has been merged. We'd love to hear how your experience was: share feedback |
Security Fix
Bumps
discord/package.json+discord/package-lock.jsononly:js-yaml ^4.3.1→^4.3.2, fixing GHSA-2883-xcg3-v3hh (maxTotalMergeKeys does not limit CPU use for empty merge sources; CWE-400/407, CVSS 7.5, availability-only). Vulnerable range>=4.0.0 <4.3.2.Sole usage site is
discord/lib/config.js:21(yaml.loadof the operator-owned hive-project.yaml), so practical risk is a bot-side CPU DoS — but the fix is a zero-API-change patch release on the same 4.x line.Verified:
npm audit --omit=devclean after bump;yaml.loadsmoke-tested with 4.3.2 against the config.js usage pattern.Claims only
discord/package.json+discord/package-lock.json— disjoint from open hold-gated PRs #6330 (src/pkg/agent), #6327 (src/pkg/hub aliases), #6309 (v4→v5 sync), #6292 (claude write roots).Fixes #6335
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-fable-5