From f69a0b7fe3c6a5119d7e6cf7ed389ad5d442f4c4 Mon Sep 17 00:00:00 2001 From: "alexandria.gomez" Date: Wed, 29 Jul 2026 19:07:30 -0400 Subject: [PATCH 1/4] fix(security): bump js-yaml, brace-expansion, fast-uri to remediate Veracode SCA flaws Fixes TFS bugs #675523, #689896, #689897, #689898, #689899, #689900: - js-yaml 4.1.1 -> 4.3.0 (CVE-2026-53550, CVE-2026-59869): backports the default-on maxTotalMergeKeys cap that bounds YAML merge-key (<<) processing - brace-expansion 2.1.1 -> 2.1.3 (CVE-2026-14257, CVE-2026-13149): bounds total expansion output length and removes the recursive post-expansion that caused exponential-time blowup on chained brace groups - fast-uri 3.1.2 -> 3.1.4 (CVE-2026-16221, CVE-2026-13676): fixes backslash authority-delimiter and IDN hostname canonicalization desync vs Node's URL All three stay within the major versions already required by eslint/ajv, so no override needed beyond bumping the pinned/floor version. Verified via a full workspace build and the lf-js-utils unit suite (362/362 passing). TFS bug #689901 (linkify-it CVE-2026-59887) is intentionally not included: the only fix ships in linkify-it 6.x, which breaks markdown-it 14.x's usage of it (named export vs. the callable default export markdown-it expects). markdown-it hasn't adopted linkify-it 6.x in any released 14.x version. Co-Authored-By: Claude Sonnet 5 --- package.json | 5 +++-- pnpm-lock.yaml | 33 +++++++++++++++++---------------- 2 files changed, 20 insertions(+), 18 deletions(-) diff --git a/package.json b/package.json index 59e3783..827c53d 100644 --- a/package.json +++ b/package.json @@ -22,12 +22,13 @@ }, "pnpm": { "overrides": { - "brace-expansion": "^2.0.3", + "brace-expansion": "^2.1.3", "flat-cache": "^4.0.0", "flatted": "^3.4.0", "form-data": "4.0.6", - "js-yaml": "4.1.1", + "js-yaml": "4.3.0", "ajv": "^8.18.0", + "fast-uri": "^3.1.4", "glob": "^10.5.0", "lodash": "^4.18.1", "markdown-it": "^14.1.1", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 6b17e45..c23abf6 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -5,12 +5,13 @@ settings: excludeLinksFromLockfile: false overrides: - brace-expansion: ^2.0.3 + brace-expansion: ^2.1.3 flat-cache: ^4.0.0 flatted: ^3.4.0 form-data: 4.0.6 - js-yaml: 4.1.1 + js-yaml: 4.3.0 ajv: ^8.18.0 + fast-uri: ^3.1.4 glob: ^10.5.0 lodash: ^4.18.1 markdown-it: ^14.1.1 @@ -970,8 +971,8 @@ packages: balanced-match@1.0.2: resolution: {integrity: sha512-3oSeUO0TMV67hN1AmbXsK4yaqU7tjiHlbxRDZOpH0KW9+CeX4bRAaX0Anxt0tx2MrpRpWwQaPwIlISEJhYU5Pw==} - brace-expansion@2.1.1: - resolution: {integrity: sha512-WR1cURNjuvBLMZBMbqM0UoE+WAfdUcEV1ccD8PVBVOI+Z3ND4+SZbN8RsfT2bMuG1qwz5RFvPukSZm5fF2D5eA==} + brace-expansion@2.1.3: + resolution: {integrity: sha512-DRdx5neNsG/QXbniLFWi2YmC/68oeOOmKz6zOjVk6ZS1ZLXgLIKqVEc6hWsmkjBbgii0SwaBTcJ5XKj5gzY/4A==} braces@3.0.3: resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==} @@ -1196,8 +1197,8 @@ packages: fast-levenshtein@2.0.6: resolution: {integrity: sha512-DCXu6Ifhqcks7TZKY3Hxp3y6qphY5SJZmrWMDrKcERSOXWQdMhU9Ig/PYrzyw/ul9jOIyh0N4M0tbC5hodg8dw==} - fast-uri@3.1.2: - resolution: {integrity: sha512-rVjf7ArG3LTk+FS6Yw81V1DLuZl1bRbNrev6Tmd/9RaroeeRRJhAt7jg/6YFxbvAQXUCavSoZhPPj6oOx+5KjQ==} + fast-uri@3.1.4: + resolution: {integrity: sha512-8JnbkQ4juDyvYs4mgFGQqg4yCYtFDtUtmp2QIQq11ZZe5CFQ5wcqm1rqDgAh/QdMySuBnPzMUiJUNZG5N/AiQw==} fastq@1.19.0: resolution: {integrity: sha512-7SFSRCNjBQIZH/xZR3iy5iQYR8aGBE0h3VG6/cwlbrpdciNYBMotQav8c1XI3HjHH+NikUpP53nPdlZSdWmFzA==} @@ -1409,8 +1410,8 @@ packages: js-tokens@4.0.0: resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==} - js-yaml@4.1.1: - resolution: {integrity: sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==} + js-yaml@4.3.0: + resolution: {integrity: sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==} hasBin: true jsdom@25.0.1: @@ -2224,7 +2225,7 @@ snapshots: globals: 13.24.0 ignore: 5.3.2 import-fresh: 3.3.1 - js-yaml: 4.1.1 + js-yaml: 4.3.0 minimatch: 9.0.9 strip-json-comments: 3.1.1 transitivePeerDependencies: @@ -2827,7 +2828,7 @@ snapshots: ajv@8.20.0: dependencies: fast-deep-equal: 3.1.3 - fast-uri: 3.1.2 + fast-uri: 3.1.4 json-schema-traverse: 1.0.0 require-from-string: 2.0.2 @@ -2859,7 +2860,7 @@ snapshots: balanced-match@1.0.2: {} - brace-expansion@2.1.1: + brace-expansion@2.1.3: dependencies: balanced-match: 1.0.2 @@ -3027,7 +3028,7 @@ snapshots: imurmurhash: 0.1.4 is-glob: 4.0.3 is-path-inside: 3.0.3 - js-yaml: 4.1.1 + js-yaml: 4.3.0 json-stable-stringify-without-jsonify: 1.0.1 levn: 0.4.1 lodash.merge: 4.6.2 @@ -3087,7 +3088,7 @@ snapshots: fast-levenshtein@2.0.6: {} - fast-uri@3.1.2: {} + fast-uri@3.1.4: {} fastq@1.19.0: dependencies: @@ -3324,7 +3325,7 @@ snapshots: js-tokens@4.0.0: {} - js-yaml@4.1.1: + js-yaml@4.3.0: dependencies: argparse: 2.0.1 @@ -3493,11 +3494,11 @@ snapshots: minimatch@3.1.5: dependencies: - brace-expansion: 2.1.1 + brace-expansion: 2.1.3 minimatch@9.0.9: dependencies: - brace-expansion: 2.1.1 + brace-expansion: 2.1.3 minipass@7.1.3: {} From 8e5f79e6c830f7963ef7acf53453f2022fd3732e Mon Sep 17 00:00:00 2001 From: "alexandria.gomez" Date: Wed, 29 Jul 2026 19:11:37 -0400 Subject: [PATCH 2/4] fix(security): bump linkify-it to remediate CVE-2026-59887 (Veracode #689901) Fixes TFS bug #689901. Prior investigation assumed the only fix was linkify-it 6.x, which breaks markdown-it's usage (named export vs. the callable default export markdown-it expects). Re-checked and found the CVE is actually already fixed in linkify-it 5.0.2 (verified in source: src_email_name's local-part is now bounded to {0,63} chars, matching the CVE's suggested RFC 5321 remediation, and the mailto validator otherwise unchanged) - no need for the breaking 6.x jump. 5.0.2 keeps the same `module.exports = LinkifyIt` CommonJS shape, and satisfies markdown-it 14.2.0's own `^5.0.1` requirement, so no override conflicts. Verified via a full workspace build, `npm run generate-docs` end-to-end (0 errors), and the lf-js-utils unit suite (362/362 passing). Co-Authored-By: Claude Sonnet 5 --- package.json | 1 + pnpm-lock.yaml | 9 +++++---- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index 827c53d..78cf6b9 100644 --- a/package.json +++ b/package.json @@ -30,6 +30,7 @@ "ajv": "^8.18.0", "fast-uri": "^3.1.4", "glob": "^10.5.0", + "linkify-it": "^5.0.2", "lodash": "^4.18.1", "markdown-it": "^14.1.1", "minimatch": "^9.0.7", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index c23abf6..0efa089 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -13,6 +13,7 @@ overrides: ajv: ^8.18.0 fast-uri: ^3.1.4 glob: ^10.5.0 + linkify-it: ^5.0.2 lodash: ^4.18.1 markdown-it: ^14.1.1 minimatch: ^9.0.7 @@ -1521,8 +1522,8 @@ packages: resolution: {integrity: sha512-NXYBzinNrblfraPGyrbPoD19C1h9lfI/1mzgWYvXUTe414Gz/X1FD2XBZSZM7rRTrMA8JL3OtAaGifrIKhQ5yQ==} engines: {node: '>= 12.0.0'} - linkify-it@5.0.1: - resolution: {integrity: sha512-wVoTjP4Q6R0NW5hiZkVJaFZPWgtXfoGF+6LucL3/FtiNjmcHhYjEr5f1Kqjirc1nBW07J/ZuRFumqr2oqccEWg==} + linkify-it@5.0.2: + resolution: {integrity: sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==} locate-path@6.0.0: resolution: {integrity: sha512-iPZK6eYjbxRu3uB4/WZ3EsEIMJFMqAoopl3R+zuq0UjcAm/MO6KCweDgPfP3elTztoKP3KtnVHxTn2NHBSDVUw==} @@ -3436,7 +3437,7 @@ snapshots: lightningcss-win32-arm64-msvc: 1.32.0 lightningcss-win32-x64-msvc: 1.32.0 - linkify-it@5.0.1: + linkify-it@5.0.2: dependencies: uc.micro: 2.1.0 @@ -3470,7 +3471,7 @@ snapshots: dependencies: argparse: 2.0.1 entities: 4.5.0 - linkify-it: 5.0.1 + linkify-it: 5.0.2 mdurl: 2.0.0 punycode.js: 2.3.1 uc.micro: 2.1.0 From 86616920a824b05f1a545b9784bd818370ae24bb Mon Sep 17 00:00:00 2001 From: "alexandria.gomez" Date: Thu, 30 Jul 2026 07:52:44 -0400 Subject: [PATCH 3/4] dummy commit to trigger build From e4d9efd8e2e22e0217442471e4d86244991bd170 Mon Sep 17 00:00:00 2001 From: "alexandria.gomez" Date: Thu, 30 Jul 2026 08:21:33 -0400 Subject: [PATCH 4/4] dummy commit again