Skip to content

SRVKP-12642,SRVKP-12660,SRVKP-12814,SRVKP-12850: added resolutions for js-yaml and protobufjs - #1219

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift-pipelines:release-v1.15.xfrom
anwesha-palit-redhat:cve/SRVKP-12660
Jul 28, 2026
Merged

SRVKP-12642,SRVKP-12660,SRVKP-12814,SRVKP-12850: added resolutions for js-yaml and protobufjs#1219
openshift-merge-bot[bot] merged 1 commit into
openshift-pipelines:release-v1.15.xfrom
anwesha-palit-redhat:cve/SRVKP-12660

Conversation

@anwesha-palit-redhat

@anwesha-palit-redhat anwesha-palit-redhat commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Refactoring
  • Migration
  • CVE Fix

Summary

Patches: Upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line.
protobufjs: This vulnerability is fixed in 7.5.8 and 8.2.0.
node-tar: This issue is fixed in version 7.5.19.
js-yaml: This issue is fixed in versions 3.15.0 and 4.3.0.

Screen Recordings

yarn why

1 15-yarnwhy

yarn test

image

yarn build

image

Screen Recordings for sanity in OCP 4.18

Screen.Recording.2026-07-28.at.16.12.12.mov
sanity-1.mov
sanity2.mov

@openshift-ci-robot

openshift-ci-robot commented Jul 28, 2026

Copy link
Copy Markdown
Collaborator

@anwesha-palit-redhat: This pull request references SRVKP-12642 which is a valid jira issue.

This pull request references SRVKP-12660 which is a valid jira issue.

This pull request references SRVKP-12814 which is a valid jira issue.

This pull request references SRVKP-12850 which is a valid jira issue.

Details

In response to this:

Type of Change

  • Bug fix
  • New feature
  • Refactoring
  • Migration
  • CVE Fix

Summary

Screen Recordings

yarn why

1 15-yarnwhy

yarn test

image

yarn build

image

Screen Recordings for sanity in OCP 4.18

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 2 🔵🔵⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Lockfile Missing

The dependency resolutions changed without a corresponding lockfile update. If CI uses an immutable or frozen install, it may fail; otherwise, the vulnerable locked versions may remain in use. Regenerate and commit the lockfile, then verify the resolved versions.

"protobufjs": "^7.5.8",
"js-yaml@^4.0.0": "4.3.0",
"js-yaml@4.1.0": "4.3.0",
"js-yaml@4.2.0": "4.3.0"

@arvindk-softwaredev arvindk-softwaredev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Looks Good to Me Label label Jul 28, 2026
@arvindk-softwaredev

Copy link
Copy Markdown
Contributor

/approve

@arvindk-softwaredev arvindk-softwaredev added the approved Label for Approved PRs label Jul 28, 2026
@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: anwesha-palit-redhat, arvindk-softwaredev

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 10dbbe1 into openshift-pipelines:release-v1.15.x Jul 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Label for Approved PRs jira/valid-reference lgtm Looks Good to Me Label

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants