From 28b2220c2bc92c0a2d284ada8998b31783e0c9bb Mon Sep 17 00:00:00 2001 From: Sphia Sadek Date: Mon, 5 Oct 2026 15:04:59 +0000 Subject: [PATCH] fix(deps): clear the http-cache-semantics osv advisory GHSA-ch52-4w7c-c8xp (CVE-2026-93748, CVSS 8.7) affects http-cache-semantics through 4.2.0. 4.3.0, published 2026-10-04, closes the upstream issue. Add a `resolutions` floor and re-resolve only that yarn.lock entry. The package is transitive through astro (`^4.2.0`), so 4.3.0 stays inside astro's range, and it isn't in jira-forge-app's lockfile. Co-Authored-By: Claude Opus 5.5 --- package.json | 1 + yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index 479db044..43286eaf 100644 --- a/package.json +++ b/package.json @@ -28,6 +28,7 @@ "devalue": "^5.9.3", "fast-uri": "^3.1.8", "fast-xml-parser": "^5.7.0", + "http-cache-semantics": "^4.3.0", "ip-address": "^10.5.1", "js-yaml": "^4.3.2", "sharp": "^0.35.4", diff --git a/yarn.lock b/yarn.lock index bd4b419d..575812f5 100644 --- a/yarn.lock +++ b/yarn.lock @@ -5830,10 +5830,10 @@ htmlparser2@^10.1.0: domutils "^3.2.2" entities "^7.0.1" -http-cache-semantics@^4.2.0: - version "4.2.0" - resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz#205f4db64f8562b76a4ff9235aa5279839a09dd5" - integrity sha512-dTxcvPXqPvXBQpq5dUr6mEMJX4oIEFv6bwom3FDwKRDsuIjjJGANqhBuoAn9c1RQJIdAKav33ED65E2ys+87QQ== +http-cache-semantics@^4.2.0, http-cache-semantics@^4.3.0: + version "4.3.0" + resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.3.0.tgz#09eead3b16c6d85552857cc3fbd888d8353a2aaf" + integrity sha512-M5t5LlJpS1UHMjvwRQVdFHvPISGeLAxNcrWuJkeGh0KxsqCHZ1O3NXZU/8x7cD0BDcGW8kapxMKTvwlqrNkHkA== http-proxy-agent@^7.0.0, http-proxy-agent@^7.0.1: version "7.0.2"