Commit ad7f9f6
fix: refresh yarn.lock to upgrade fast-xml-builder to ^1.2.0 (CVE-2026-44664, CVE-2026-44665) (#1184)
* fix: upgrade fast-xml-builder to ^1.1.7 to address CVE-2026-44665
Co-authored-by: Brendan Kellam <brendan@sourcebot.dev>
* Update CHANGELOG.md for PR #1184
Co-authored-by: Brendan Kellam <brendan@sourcebot.dev>
* fix: refresh yarn.lock to upgrade fast-xml-builder to ^1.2.0 (CVE-2026-44664, CVE-2026-44665)
Replaces the prior resolution-override approach with a lockfile refresh.
The existing fast-xml-builder@^1.1.5 range already admits the patched
1.2.0; the lockfile was just stale.
Also consolidates SOU-1073 / CVE-2026-44664 (previously #1185) into this
PR — same package release fixes both sibling CVEs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 9dbc3f9 commit ad7f9f6
2 files changed
Lines changed: 13 additions & 11 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| 17 | + | |
17 | 18 | | |
18 | 19 | | |
19 | 20 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13678 | 13678 | | |
13679 | 13679 | | |
13680 | 13680 | | |
13681 | | - | |
13682 | | - | |
| 13681 | + | |
| 13682 | + | |
13683 | 13683 | | |
13684 | | - | |
13685 | | - | |
| 13684 | + | |
| 13685 | + | |
| 13686 | + | |
13686 | 13687 | | |
13687 | 13688 | | |
13688 | 13689 | | |
| |||
18036 | 18037 | | |
18037 | 18038 | | |
18038 | 18039 | | |
18039 | | - | |
18040 | | - | |
18041 | | - | |
18042 | | - | |
18043 | | - | |
18044 | | - | |
18045 | | - | |
18046 | 18040 | | |
18047 | 18041 | | |
18048 | 18042 | | |
| |||
22593 | 22587 | | |
22594 | 22588 | | |
22595 | 22589 | | |
| 22590 | + | |
| 22591 | + | |
| 22592 | + | |
| 22593 | + | |
| 22594 | + | |
| 22595 | + | |
| 22596 | + | |
22596 | 22597 | | |
22597 | 22598 | | |
22598 | 22599 | | |
| |||
0 commit comments