Skip to content

Update serialize-javascript package to fix vulnerability#22217

Open
sanjays-ms wants to merge 20 commits into
masterfrom
users/v-sanjayse/serialize-javascript-overrides
Open

Update serialize-javascript package to fix vulnerability#22217
sanjays-ms wants to merge 20 commits into
masterfrom
users/v-sanjayse/serialize-javascript-overrides

Conversation

@sanjays-ms
Copy link
Copy Markdown
Contributor

@sanjays-ms sanjays-ms commented May 28, 2026

Context

AB#2362576


Task Name

ANTV1, AzureSpringCloudV0, BicepDeployV0, GradleV2, GradleV3, GradleV4, MavenV2, MavenV3, MavenV4, PublishCodeCoverageResultsV1


Description

Update / override the serialize-javascript pacakge

This is a dependency as part of the mocha package we use for testing.
Since the package is only for testing no functionality change of any tasks

Mocha latest version doesn't have fix for this so we are adding overrides

Even though couple of tasks have only Test folders update bumped versions to keep versioning as per repository guidelines

To avoid conflicts with other PRs I have moved the version to x.275.3 for the tasks


Risk Assessment (Low / Medium / High)

Low - single package update mostly testing / dev dependency


Change Behind Feature Flag (Yes / No)

No


Tech Design / Approach

NA


Documentation Changes Required (Yes/No)

No


Unit Tests Added or Updated (Yes / No)

No


Additional Testing Performed

Testing only performed as part of CI checks. No manual testing performed


Logging Added/Updated (Yes/No)

NA


Telemetry Added/Updated (Yes/No)

No


Rollback Scenario and Process (Yes/No)

Override task if any failures and fix the task and bump version.


Dependency Impact Assessed and Regression Tested (Yes/No)

  • All impacted internal modules, APIs, services, and third-party libraries are analyzed.
  • Results are reviewed and confirmed to not break existing functionality.

Checklist

  • Related issue linked (if applicable)
  • Task version was bumped — see versioning guide
  • Verified the task behaves as expected

@sanjays-ms sanjays-ms requested review from a team and tarunramsinghani as code owners May 28, 2026 09:30
@sanjays-ms sanjays-ms force-pushed the users/v-sanjayse/serialize-javascript-overrides branch from 7815fc4 to 24bcef0 Compare May 29, 2026 01:59
@sanjays-ms
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@sanjays-ms sanjays-ms force-pushed the users/v-sanjayse/serialize-javascript-overrides branch from 24bcef0 to b75162f Compare May 29, 2026 03:29
@sanjays-ms
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@dingmeng-xue
Copy link
Copy Markdown
Contributor

OK for AzureSpringCloudV0

@sanjays-ms sanjays-ms force-pushed the users/v-sanjayse/serialize-javascript-overrides branch from b75162f to 85f0dea Compare June 1, 2026 04:22
@sanjays-ms
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants