be8102c4a4
## Summary Closes the last open Dependabot alert on `main` — [alert 1504](https://github.com/twentyhq/twenty/security/dependabot/1504) (GHSA-h67p-54hq-rp68 / CVE-2026-53550, js-yaml merge-key quadratic-complexity DoS; medium, dev scope). The 4.x js-yaml copies are already pinned to 4.2.0 (the seven `@mintlify/*` + `@verdaccio/config` resolutions). The remaining vulnerable copy was **js-yaml 3.14.2**, held by two `^3.13.1` consumers with no fixed upstream release: - `@istanbuljs/load-nyc-config@1.1.0` (jest coverage) - `front-matter@4.0.2` (mintlify docs tooling — EOL, latest is 4.0.2) ## Approach Both are forced to **js-yaml 4.2.0** via scoped resolutions, which evicts the 3.x copy entirely: ```jsonc "front-matter/js-yaml": "4.2.0", "@istanbuljs/load-nyc-config/js-yaml": "4.2.0", ``` - **load-nyc-config** already calls `yaml.load` (present + safe-by-default in 4.x), so its pin alone works. - **front-matter** crashed on js-yaml 4.x because its default loader called the removed `safeLoad`, so it's also **patched** (`.yarn/patches/front-matter-npm-4.0.2-e1cc0efa69.patch`): ```diff - var loader = allowUnsafe ? parser.load : parser.safeLoad + var loader = parser.load ``` On 4.x `load` is already safe-by-default and there's no full/unsafe schema, so the `allowUnsafe` ternary is dead. **Why the version move is a separate resolution, not folded into the patch:** a `yarn patch` only rewrites a package's *files* — it does **not** change the resolved dependency graph. Bumping js-yaml inside the patched `package.json` is ignored by resolution (verified: front-matter@patch still pulled 3.14.2 until the explicit pin was added). This is the repo's first *transitive* patch; like every other transitive override it lives in root `resolutions`. Documented in the `//resolutions` note. ## Verification - js-yaml 3.x **fully evicted** — the tree resolves js-yaml to **4.2.0 only** (no `^3.13.1` descriptor remains). - `yarn install --immutable` passes. - front-matter parses real docs front-matter correctly on 4.2.0 (unit smoke test). - **`mintlify validate` passes** — the docs toolchain builds with the patched front-matter.
14 lines
464 B
Diff
14 lines
464 B
Diff
diff --git a/index.js b/index.js
|
|
index d518f1df0974b361911ab5ed90857295ab834f0a..919937ce987cf89fb5718837970406d1cd5bfc4b 100644
|
|
--- a/index.js
|
|
+++ b/index.js
|
|
@@ -59,7 +59,7 @@ function parse (string, allowUnsafe) {
|
|
}
|
|
}
|
|
|
|
- var loader = allowUnsafe ? parser.load : parser.safeLoad
|
|
+ var loader = parser.load
|
|
var yaml = match[match.length - 1].replace(/^\s+|\s+$/g, '')
|
|
var attributes = loader(yaml) || {}
|
|
var body = string.replace(match[0], '')
|