Skip to content

fix(deps): vuln serialize-javascript (major → 7.0.5) #37535

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
masterfrom
engraver-auto-version-upgrade/major/npm/3-1781564417
Open

fix(deps): vuln serialize-javascript (major → 7.0.5) #37535
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
masterfrom
engraver-auto-version-upgrade/major/npm/3-1781564417

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • . (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
serialize-javascript 2.1.2 7.0.5 major Direct 3 HIGH

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (3 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
serialize-javascript GHSA-5c6j-r48x-rmvq HIGH Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() 2.1.2 7.0.3
serialize-javascript GHSA-hxcc-f52p-wc94 HIGH Insecure serialization leading to RCE in serialize-javascript 2.1.2 3.1.0
serialize-javascript CVE-2020-7660 HIGH - 2.1.2 -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented Jun 18, 2026

Copy link
Copy Markdown
Author

Auto-rebase failed

Lockfile regeneration failed during rebase onto master. Your branch was not updated. You may need to rebase and regenerate lockfiles manually.

Error details

child workflow execution error (type: engraver.Engraver_AllManagersWorkflow, workflowID: 019ee232-aae0-77e1-ba70-cb02e49f64df_57, runID: 019ee235-2cb5-7858-b27e-2280d86c34a1, initiatedEventID: 57, startedEventID: 58): activity error (type: engraver.Engraver_GetChanges, scheduledEventID: 8, startedEventID: 9, identity: 1@engraver-worker-54fc6f45bb-hrxk8@): unable to clone github repository: git clone failed: exit status 128 (type: wrapError, retryable: true): git clone failed: exit status 128 (type: wrapError, retryable: true): exit status 128 (type: ExitError, retryable: true)


Auto-Rebase · Add no-auto-rebase to opt out

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented Jun 22, 2026

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with master — rebased onto f334966.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-6bb5b9 dd-octo-sts-6bb5b9 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from c7e0bea to 4665203 Compare June 22, 2026 12:04
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 4665203 to d9247ec Compare June 22, 2026 14:04
@dd-octo-sts-26fcfa dd-octo-sts-26fcfa Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from d9247ec to 778528b Compare June 22, 2026 15:06
@dd-octo-sts-09fbc5 dd-octo-sts-09fbc5 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 778528b to 6caf82f Compare June 22, 2026 15:27
@dd-octo-sts-4aefcb dd-octo-sts-4aefcb Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 6caf82f to fde243f Compare June 22, 2026 15:48
@dd-octo-sts-0c48d7 dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from fde243f to 6394d60 Compare June 22, 2026 16:05
@dd-octo-sts-2c363b dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 6394d60 to 05a283f Compare June 22, 2026 16:22
@dd-octo-sts-4caf68 dd-octo-sts-4caf68 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 05a283f to b9b60d7 Compare June 22, 2026 16:37
@dd-octo-sts-4aefcb dd-octo-sts-4aefcb Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from b9b60d7 to 8459a0f Compare June 22, 2026 16:47
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 8459a0f to 4207626 Compare June 22, 2026 17:25
@dd-octo-sts-2c363b dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 4207626 to 9663305 Compare June 22, 2026 18:11
@dd-octo-sts-150931 dd-octo-sts-150931 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 9663305 to e53d174 Compare June 22, 2026 19:26
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from e53d174 to 09446bd Compare June 23, 2026 07:46
@dd-octo-sts-09fbc5 dd-octo-sts-09fbc5 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 09446bd to eedfb4a Compare June 23, 2026 13:50
@dd-octo-sts-94e5d1 dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from eedfb4a to 009f604 Compare June 23, 2026 14:06
@dd-octo-sts-b8cf80 dd-octo-sts-b8cf80 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 009f604 to e349cdc Compare June 23, 2026 14:18
@dd-octo-sts-c33ac5 dd-octo-sts-c33ac5 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from e349cdc to afb15fb Compare June 23, 2026 15:23
@dd-octo-sts-2c363b dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from afb15fb to a221be9 Compare June 23, 2026 16:03
@dd-octo-sts-6bb5b9 dd-octo-sts-6bb5b9 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from a221be9 to eda62ee Compare June 23, 2026 16:20
@dd-octo-sts-6bb5b9 dd-octo-sts-6bb5b9 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from f4c5fd4 to dbc6631 Compare June 24, 2026 15:07
@dd-octo-sts-dcc400 dd-octo-sts-dcc400 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from dbc6631 to 7a767e5 Compare June 24, 2026 15:26
@dd-octo-sts-b8cf80 dd-octo-sts-b8cf80 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 7a767e5 to 1075f8f Compare June 24, 2026 16:09
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 1075f8f to 6fa1708 Compare June 24, 2026 16:31
@dd-octo-sts dd-octo-sts Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 6fa1708 to 05df258 Compare June 24, 2026 16:42
@dd-octo-sts-6bb5b9 dd-octo-sts-6bb5b9 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 05df258 to e831d26 Compare June 24, 2026 17:31
@dd-octo-sts-03ec73 dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from e831d26 to 313f37c Compare June 24, 2026 18:03
@dd-octo-sts-4191dd dd-octo-sts-4191dd Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 313f37c to 2484d9d Compare June 24, 2026 18:28
@dd-octo-sts-b8cf80 dd-octo-sts-b8cf80 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 2484d9d to b68e79a Compare June 24, 2026 19:45
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase failed

Lockfile regeneration failed during rebase onto master. Your branch was not updated. You may need to rebase and regenerate lockfiles manually.

Error details

child workflow execution error (type: engraver.Engraver_AllManagersWorkflow, workflowID: 019efb37-6582-7231-9587-0fd94ae2ad9b_57, runID: 019efb3e-b6b9-73c1-bd5d-d89107850044, initiatedEventID: 57, startedEventID: 58): Child workflow timeout (type: StartToClose)


Auto-Rebase · Add no-auto-rebase to opt out

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented Jun 24, 2026

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with master — rebased onto 6ceb1ba.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-0c48d7 dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from b68e79a to a808c40 Compare June 24, 2026 20:36
@dd-octo-sts-aad58d dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from a808c40 to 0aa4f8c Compare June 24, 2026 20:55
@dd-octo-sts-6354d5 dd-octo-sts-6354d5 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 0aa4f8c to ef22e1c Compare June 24, 2026 21:03
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase failed

Could not update your branch. This may be due to a concurrent update; the next push to master will retry automatically.

Error details

canceled


Auto-Rebase · Add no-auto-rebase to opt out

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented Jun 25, 2026

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with master — rebased onto ca10329.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts dd-octo-sts Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from ef22e1c to ab77ff4 Compare June 25, 2026 07:07
@dd-octo-sts-2c363b dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from ab77ff4 to ba46745 Compare June 25, 2026 07:38
@dd-octo-sts-019303 dd-octo-sts-019303 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from ba46745 to 038cbae Compare June 25, 2026 09:45
@dd-octo-sts-aad58d dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 038cbae to 08ec034 Compare June 25, 2026 10:08
@dd-octo-sts-0c48d7 dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 08ec034 to 8634268 Compare June 25, 2026 10:30
@dd-octo-sts-dcc400 dd-octo-sts-dcc400 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 8634268 to da74c90 Compare June 25, 2026 15:16
@dd-octo-sts-6354d5 dd-octo-sts-6354d5 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from da74c90 to 62f9b8b Compare June 25, 2026 15:25
@dd-octo-sts dd-octo-sts Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 62f9b8b to 5a131cc Compare June 25, 2026 15:55
@dd-octo-sts-0c48d7 dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 5a131cc to 551e8cb Compare June 25, 2026 16:33
@dd-octo-sts-94e5d1 dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 551e8cb to 3726b17 Compare June 25, 2026 17:55
@dd-octo-sts-4caf68 dd-octo-sts-4caf68 Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 3726b17 to 5926564 Compare June 25, 2026 18:33
@dd-octo-sts-aad58d dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/major/npm/3-1781564417 branch from 5926564 to dd57e9c Compare June 25, 2026 18:41
dd-octo-sts-dcc400 Bot and others added 2 commits June 25, 2026 23:04
Co-authored-by: dd-octo-sts-4aefcb[bot] <266798660+dd-octo-sts-4aefcb[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-4aefcb[bot] <266798660+dd-octo-sts-4aefcb[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants