Skip to content

Bump tmp to 0.2.6 in yoga to fix GHSA-ph9p-34f9-6g65#1986

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D110195946
Closed

Bump tmp to 0.2.6 in yoga to fix GHSA-ph9p-34f9-6g65#1986
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D110195946

Conversation

@rozele

@rozele rozele commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

Summary:
Resolves the GitHub security alert for the tmp npm package in the facebook/yoga project (T273208322).

tmp < 0.2.6 is affected by GHSA-ph9p-34f9-6g65 / CVE-2026-44705 (high severity). It is a transitive dependency pulled in via selenium-webdriver in the gentest workspace.

This bumps the tmp@^0.2.5 entry in xplat/yoga/yarn.lock from 0.2.5 to the fixed 0.2.6, updating the resolved URL and integrity hash. The ^0.2.5 range already satisfies 0.2.6, and tmp@0.2.6 has no dependencies, so no other lockfile entries change.

Differential Revision: D110195946

Summary:
Resolves the GitHub security alert for the `tmp` npm package in the facebook/yoga project (T273208322).

`tmp` < 0.2.6 is affected by GHSA-ph9p-34f9-6g65 / CVE-2026-44705 (high severity). It is a transitive dependency pulled in via `selenium-webdriver` in the `gentest` workspace.

This bumps the `tmp@^0.2.5` entry in `xplat/yoga/yarn.lock` from 0.2.5 to the fixed 0.2.6, updating the resolved URL and integrity hash. The `^0.2.5` range already satisfies 0.2.6, and tmp@0.2.6 has no dependencies, so no other lockfile entries change.

Differential Revision: D110195946
@meta-cla meta-cla Bot added the CLA Signed label Jun 30, 2026
@meta-codesync

meta-codesync Bot commented Jun 30, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D110195946.

@meta-codesync

meta-codesync Bot commented Jun 30, 2026

Copy link
Copy Markdown

This pull request has been merged in 53fccc9.

@meta-codesync meta-codesync Bot added the Merged label Jun 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant