fix(deps): pin five vulnerable npm packages via Yarn resolutions - #913
Merged
Merged
Conversation
Closes eight open high-severity Dependabot alerts on kotlin-js-store/yarn.lock: js-yaml, socket.io-parser, fast-uri, serialize-javascript and brace-expansion. Regenerating the lockfiles on develop is a zero-line diff. Yarn 1 keeps a locked version for as long as it still satisfies the requested range, so these entries never move on their own even though every one of them had a patched release inside its existing range. A Yarn resolution is what actually forces the version, which is what sk.ainet.npm-pins writes. brace-expansion needed one pin to cover two major lines: minimatch 3.x asks for ^1.1.7 and minimatch 9.x for ^2.0.2, and a resolution is global. 2.1.4 clears the fixed set of both advisories and the exported API is unchanged across the major. serialize-javascript 6 -> 7 overrides what mocha 11.7.5 requests. Yarn warns and applies it; its only use is mocha parallel-mode worker serialization and the web test suites pass. kotlin-js-store/wasm/yarn.lock grows because Yarn writes an entry for every resolutions key whether or not the package is in that graph. Those packages are not imported by the wasm build; noted in the catalog. Left open deliberately: webpack (KGP pins it exactly) and diff (semver -major override of a mocha-only dependency for a low finding). Verified with kotlinUpgradeYarnLock, kotlinWasmUpgradeYarnLock, verifyNpmPins, jsTest, wasmJsTest and wasmWasiTest.
aharakal
approved these changes
Aug 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes 8 open Dependabot alerts — all
high— inkotlin-js-store/yarn.lock, using thesk.ainet.npm-pinsmechanism added in #900.Why pins and not a lockfile refresh
./gradlew kotlinUpgradeYarnLock kotlinWasmUpgradeYarnLockon a cleandevelopproduces a zero-line diff. Yarn 1 keeps a locked version as long as it still satisfies the requested range, so a stale-but-satisfying entry never moves on its own — even though every one of these packages had a patched release inside its existing range. A Yarnresolutionis what actually forces the version, which is exactly whatnpmPinswrites.Pins added
js-yamlsocket.io-parserfast-uriserialize-javascriptbrace-expansionTwo notes on the last two rows:
brace-expansionhad two major lines in the graph —minimatch@3.xrequests^1.1.7,minimatch@9.xrequests^2.0.2— and a Yarn resolution is global, so one pin has to cover both. 2.1.4 clears the fixed set of both advisories (<1.1.18and>=2.0.0 <2.1.4). The exported API (expand(str)) is unchanged across the major, and 2.x drops theconcat-mapdependency, so the lockfile gets slightly smaller.serialize-javascript6 → 7 is a semver-major override of whatmocha@11.7.5asks for. Yarn logsResolution field "serialize-javascript@7.0.5" is incompatible with requested version "serialize-javascript@^6.0.2"and applies it anyway. Its only consumer is mocha's parallel-mode worker serialization, andjsTest/wasmJsTest/wasmWasiTestpass.Expected: the wasm lockfile grew
kotlin-js-store/wasm/yarn.lockpreviously held onlyws; it now also listsjs-yaml,socket.io-parser,serialize-javascript,fast-uri,brace-expansionand their transitives. Yarn writes a lockfile entry for everyresolutionskey whether or not the package is in that graph, andnpmPinsapplies each pin to both Yarn roots by design. Harmless — those packages are not imported by the wasm build — and it is the price of one declaration covering both targets. Noted in thelibs.versions.tomlcomment block so the next person does not read it as a real dependency.Not fixed here
Three low-severity alerts are left open on purpose:
webpack(GHSA-8fgc-7cc6-rx7x, GHSA-38r7-794h-5758) — KGP pins webpack to an exact5.101.3. Overriding it decouples the bundler from the version the Kotlin toolchain was tested against; better handled by a KGP bump.diff(GHSA-73rr-hh4g-fpgx) — needs 7.0.0 → 8.0.3, a semver-major override of a mocha-only dependency, for alowfinding.All five remaining npm alerts, and all five fixed here, are in the Kotlin/JS test and bundling toolchain — none of them reach a published
sk.ainet.core:*artifact.Verification