Skip to content

fix(deps): pin five vulnerable npm packages via Yarn resolutions - #913

Merged
michalharakal merged 1 commit into
developfrom
fix/npm-lockfile-vulnerabilities
Aug 9, 2026
Merged

michalharakal merged 1 commit into
developfrom
fix/npm-lockfile-vulnerabilities

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Closes 8 open Dependabot alerts — all high — in kotlin-js-store/yarn.lock, using the sk.ainet.npm-pins mechanism added in #900.

Why pins and not a lockfile refresh

./gradlew kotlinUpgradeYarnLock kotlinWasmUpgradeYarnLock on a clean develop produces a zero-line diff. Yarn 1 keeps a locked version as long as it still satisfies the requested range, so a stale-but-satisfying entry never moves on its own — even though every one of these packages had a patched release inside its existing range. A Yarn resolution is what actually forces the version, which is exactly what npmPins writes.

Pins added

Package Was Now Advisories
js-yaml 4.3.0 4.3.1 GHSA-5p4m-2wfm-xmqj
socket.io-parser 4.2.6 4.2.7 GHSA-2m8v-j782-fhvr
fast-uri 3.1.3 3.1.5 GHSA-7p8r-x3mc-p8w7, GHSA-v2hh-gcrm-f6hx
serialize-javascript 6.0.2 7.0.5 GHSA-5c6j-r48x-rmvq, GHSA-qj8w-gfj5-8c6v
brace-expansion 1.1.16 + 2.1.2 2.1.4 GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg

Two notes on the last two rows:

  • brace-expansion had two major lines in the graph — minimatch@3.x requests ^1.1.7, minimatch@9.x requests ^2.0.2 — and a Yarn resolution is global, so one pin has to cover both. 2.1.4 clears the fixed set of both advisories (<1.1.18 and >=2.0.0 <2.1.4). The exported API (expand(str)) is unchanged across the major, and 2.x drops the concat-map dependency, so the lockfile gets slightly smaller.
  • serialize-javascript 6 → 7 is a semver-major override of what mocha@11.7.5 asks for. Yarn logs Resolution field "serialize-javascript@7.0.5" is incompatible with requested version "serialize-javascript@^6.0.2" and applies it anyway. Its only consumer is mocha's parallel-mode worker serialization, and jsTest / wasmJsTest / wasmWasiTest pass.

Expected: the wasm lockfile grew

kotlin-js-store/wasm/yarn.lock previously held only ws; it now also lists js-yaml, socket.io-parser, serialize-javascript, fast-uri, brace-expansion and their transitives. Yarn writes a lockfile entry for every resolutions key whether or not the package is in that graph, and npmPins applies each pin to both Yarn roots by design. Harmless — those packages are not imported by the wasm build — and it is the price of one declaration covering both targets. Noted in the libs.versions.toml comment block so the next person does not read it as a real dependency.

Not fixed here

Three low-severity alerts are left open on purpose:

  • webpack (GHSA-8fgc-7cc6-rx7x, GHSA-38r7-794h-5758) — KGP pins webpack to an exact 5.101.3. Overriding it decouples the bundler from the version the Kotlin toolchain was tested against; better handled by a KGP bump.
  • diff (GHSA-73rr-hh4g-fpgx) — needs 7.0.0 → 8.0.3, a semver-major override of a mocha-only dependency, for a low finding.

All five remaining npm alerts, and all five fixed here, are in the Kotlin/JS test and bundling toolchain — none of them reach a published sk.ainet.core:* artifact.

Verification

./gradlew kotlinUpgradeYarnLock kotlinWasmUpgradeYarnLock   # regenerated, committed
./gradlew verifyNpmPins jsTest wasmJsTest wasmWasiTest      # green

Closes eight open high-severity Dependabot alerts on
kotlin-js-store/yarn.lock: js-yaml, socket.io-parser, fast-uri,
serialize-javascript and brace-expansion.

Regenerating the lockfiles on develop is a zero-line diff. Yarn 1 keeps a
locked version for as long as it still satisfies the requested range, so
these entries never move on their own even though every one of them had a
patched release inside its existing range. A Yarn resolution is what
actually forces the version, which is what sk.ainet.npm-pins writes.

brace-expansion needed one pin to cover two major lines: minimatch 3.x
asks for ^1.1.7 and minimatch 9.x for ^2.0.2, and a resolution is global.
2.1.4 clears the fixed set of both advisories and the exported API is
unchanged across the major.

serialize-javascript 6 -> 7 overrides what mocha 11.7.5 requests. Yarn
warns and applies it; its only use is mocha parallel-mode worker
serialization and the web test suites pass.

kotlin-js-store/wasm/yarn.lock grows because Yarn writes an entry for
every resolutions key whether or not the package is in that graph. Those
packages are not imported by the wasm build; noted in the catalog.

Left open deliberately: webpack (KGP pins it exactly) and diff (semver
-major override of a mocha-only dependency for a low finding).

Verified with kotlinUpgradeYarnLock, kotlinWasmUpgradeYarnLock,
verifyNpmPins, jsTest, wasmJsTest and wasmWasiTest.
@michalharakal
michalharakal requested review from MacOS and aharakal August 9, 2026 11:29
@michalharakal
michalharakal merged commit 171638b into develop Aug 9, 2026
13 checks passed
@michalharakal
michalharakal deleted the fix/npm-lockfile-vulnerabilities branch August 9, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants