Skip to content

fix(deps): vuln minor upgrades — 4 packages (minor: 3 · patch: 1) [package.json] - #1443

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1790583591
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1790583591

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 4 packages upgraded (MINOR changes included)

Manifests changed:

  • package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
dd-trace 5.56.0 5.128.0 minor Direct 2 HIGH
smol-toml 1.6.1 1.9.0 minor Transitive 2 HIGH
ajv 6.12.6 6.15.0 minor Transitive 2 MEDIUM
fast-xml-parser 4.5.5 4.5.7 patch Transitive 2 MEDIUM

Security Details

🚨 Critical & High Severity (4 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
dd-trace GHSA-wxqq-gcq8-c443 HIGH dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS 5.56.0 5.100.0 -
dd-trace CVE-2026-50272 HIGH dd-trace: Improper parsing of W3C baggage headers may lead to DoS 5.56.0 - -
smol-toml GHSA-7w5x-hrqm-74c2 HIGH smol-toml: Denial of Service via malformed TOML documents 1.6.1 1.7.1 -
smol-toml CVE-2026-85730 HIGH smol-toml: Denial of Service via malformed TOML documents 1.6.1 - -
ℹ️ Other Vulnerabilities (4)
Package CVE Severity Summary Unsafe Version Fixed In Case
ajv GHSA-2g4f-4pwh-qvx6 MODERATE ajv has ReDoS when using $data option 6.12.6 8.18.0 -
ajv CVE-2025-69873 MODERATE - 6.12.6 - -
fast-xml-parser GHSA-gh4j-gqv2-49f6 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.5.5 5.7.0 -
fast-xml-parser CVE-2026-41650 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.5.5 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-4

datadog-prod-us1-4 Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: e8d934b | Docs | View more details | Give us feedback!

dd-octo-sts-94e5d1 Bot and others added 2 commits September 28, 2026 20:19
….json]

Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with develop — rebased onto 4f9364f.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-94e5d1
dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/npm/0-1790583591 branch from 66e1a9f to e8d934b Compare September 28, 2026 20:19
@dd-octo-sts
dd-octo-sts Bot marked this pull request as ready for review September 29, 2026 19:15
@dd-octo-sts
dd-octo-sts Bot requested a review from a team as a code owner September 29, 2026 19:15
Copilot AI balanced review requested due to automatic review settings September 29, 2026 19:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The AJV and smol-toml lock entries remain vulnerable, while the selected fast-xml-parser version does not contain the cited fix.

Review effort: Balanced
Findings: 2 High severity

Open (2)
What changed in this PR

Updates JavaScript dependencies to address reported vulnerabilities.

Changes:

  • Upgrades dd-trace and its transitive dependencies.
  • Attempts to override vulnerable AJV and smol-toml versions.
  • Updates fast-xml-parser, but not to the advisory’s fixed version.
File Description
package.json Updates dependency constraints and resolutions.
yarn.lock Records the dd-trace and fast-xml-parser dependency changes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
"ejs": "3.1.10",
"cross-spawn": "7.0.5",
"fast-xml-parser": "4.5.5",
"fast-xml-parser": "^4.5.7",
Comment thread package.json
Comment on lines +148 to +149
"ajv@npm:^6.10.0": "npm:^6.15.0",
"ajv@npm:^6.12.4": "npm:^6.15.0",
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants