Skip to content

fix(security): pin serialize-javascript to >=7.0.5 via npm overrides …#1097

Merged
yash6195 merged 1 commit into
pre_prodfrom
security/fix-serialize-javascript-rce-aps-18800
May 7, 2026
Merged

fix(security): pin serialize-javascript to >=7.0.5 via npm overrides …#1097
yash6195 merged 1 commit into
pre_prodfrom
security/fix-serialize-javascript-rce-aps-18800

Conversation

@yash6195
Copy link
Copy Markdown
Collaborator

@yash6195 yash6195 commented May 7, 2026

APS-18800

Fixes GHSA-5c6j-r48x-rmvq (RCE) and GHSA-qj8w-gfj5-8c6v (DoS) in the transitive serialize-javascript dependency pulled in by mocha. Uses npm's native overrides field — no third-party workarounds needed.

…[APS-18800]

Fixes GHSA-5c6j-r48x-rmvq (RCE) and GHSA-qj8w-gfj5-8c6v (DoS) in the
transitive serialize-javascript dependency pulled in by mocha. Uses npm's
native `overrides` field — no third-party workarounds needed.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@yash6195 yash6195 merged commit 088ddaa into pre_prod May 7, 2026
5 checks passed
@dheerajbstack dheerajbstack deleted the security/fix-serialize-javascript-rce-aps-18800 branch May 8, 2026 07:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants