fix: resolve CVE-2026-34043 in serialize-javascript
Some checks are pending
Argos CI Screenshots / take screenshots (push) Waiting to run
Publish codecov report from main branch / Run tests and push coverage result (push) Waiting to run
e2e-kubernetes-tests-main / Run All E2E tests (push) Waiting to run
e2e-tests-main / Run E2E tests - flatpak-build (push) Waiting to run
e2e-tests-main / Run E2E tests - source-build (push) Waiting to run
e2e-tests-main / windows-11-arm update e2e tests - custom-extensions (push) Waiting to run
e2e-tests-main / windows-2025 update e2e tests - custom-extensions (push) Waiting to run
e2e-tests-main / windows-11-arm update e2e tests - vanilla (push) Waiting to run
e2e-tests-main / windows-2025 update e2e tests - vanilla (push) Waiting to run
e2e-tests-main / macos-15-intel update e2e tests (push) Waiting to run
e2e-tests-main / macos-26 update e2e tests (push) Waiting to run
Managed configuration tests / Managed configuration tests - macos-latest (push) Waiting to run
Managed configuration tests / Managed configuration tests - ubuntu-latest (push) Waiting to run
Managed configuration tests / Managed configuration tests - windows-2025 (push) Waiting to run
next build / Tagging (push) Waiting to run
next build / Build / macos-15 (push) Blocked by required conditions
next build / Build / ubuntu-24.04 (push) Blocked by required conditions
next build / Build / windows-2025 (push) Blocked by required conditions
next build / Release (push) Blocked by required conditions
Publish NPM packages to npmjs.com using OIDC / Prepare version info (push) Waiting to run
Publish NPM packages to npmjs.com using OIDC / Publish to npm (push) Blocked by required conditions
Scorecard supply-chain security / Scorecard analysis (push) Waiting to run
Publish Website / Build and deploy website (push) Waiting to run

Upgrade serialize-javascript to satisfy >=7.0.5
Advisory: https://github.com/advisories/GHSA-qj8w-gfj5-8c6v

Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Florent Benoit <fbenoit@redhat.com>
This commit is contained in:
Florent Benoit 2026-04-20 17:41:13 +02:00 committed by Florent BENOIT
parent cbe635999f
commit 2852e4572a
2 changed files with 10 additions and 10 deletions

View file

@ -226,7 +226,7 @@
"picomatch@^2": "^2.3.2",
"picomatch@^3": "^3.0.2",
"picomatch@^4": "^4.0.4",
"serialize-javascript": "^7.0.4",
"serialize-javascript": "^7.0.5",
"ajv@^6": "^6.14.0",
"ajv@^8": "^8.18.0",
"electron-builder-squirrel-windows": "^26.8.2",

View file

@ -34,7 +34,7 @@ overrides:
picomatch@^2: ^2.3.2
picomatch@^3: ^3.0.2
picomatch@^4: ^4.0.4
serialize-javascript: ^7.0.4
serialize-javascript: ^7.0.5
ajv@^6: ^6.14.0
ajv@^8: ^8.18.0
electron-builder-squirrel-windows: ^26.8.2
@ -10673,8 +10673,8 @@ packages:
resolution: {integrity: sha512-8I8TjW5KMOKsZQTvoxjuSIa7foAwPWGOts+6o7sgjz41/qMD9VQHEDxi6PBvK2l0MXUmqZyNpUK+T2tQaaElvw==}
engines: {node: '>=10'}
serialize-javascript@7.0.4:
resolution: {integrity: sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==}
serialize-javascript@7.0.5:
resolution: {integrity: sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==}
engines: {node: '>=20.0.0'}
serve-handler@6.1.6:
@ -18385,7 +18385,7 @@ snapshots:
globby: 13.2.2
normalize-path: 3.0.0
schema-utils: 4.2.0
serialize-javascript: 7.0.4
serialize-javascript: 7.0.5
webpack: 5.105.0
copyfiles@2.4.1:
@ -18509,7 +18509,7 @@ snapshots:
jest-worker: 29.7.0
postcss: 8.5.10
schema-utils: 4.2.0
serialize-javascript: 7.0.4
serialize-javascript: 7.0.5
webpack: 5.105.0
optionalDependencies:
clean-css: 5.3.3
@ -24150,7 +24150,7 @@ snapshots:
type-fest: 0.13.1
optional: true
serialize-javascript@7.0.4: {}
serialize-javascript@7.0.5: {}
serve-handler@6.1.6:
dependencies:
@ -24865,7 +24865,7 @@ snapshots:
'@jridgewell/trace-mapping': 0.3.31
jest-worker: 27.5.1
schema-utils: 3.3.0
serialize-javascript: 7.0.4
serialize-javascript: 7.0.5
terser: 5.36.0
webpack: 5.105.0
@ -24874,7 +24874,7 @@ snapshots:
'@jridgewell/trace-mapping': 0.3.31
jest-worker: 27.5.1
schema-utils: 4.3.3
serialize-javascript: 7.0.4
serialize-javascript: 7.0.5
terser: 5.36.0
webpack: 5.105.0(esbuild@0.25.12)
optionalDependencies:
@ -24886,7 +24886,7 @@ snapshots:
'@jridgewell/trace-mapping': 0.3.31
jest-worker: 27.5.1
schema-utils: 4.3.3
serialize-javascript: 7.0.4
serialize-javascript: 7.0.5
terser: 5.36.0
webpack: 5.105.0