Skip to content

chore: upgrade esbuild to ^0.28.1 to address GHSA-g7r4-m6w7-qqqr#1342

Merged
brendan-kellam merged 1 commit into
mainfrom
linear/sou-1371-sourcebot-devsourcebot-ghsa-g7r4-m6w7-qqqr-esbuild-870e
Jun 17, 2026
Merged

chore: upgrade esbuild to ^0.28.1 to address GHSA-g7r4-m6w7-qqqr#1342
brendan-kellam merged 1 commit into
mainfrom
linear/sou-1371-sourcebot-devsourcebot-ghsa-g7r4-m6w7-qqqr-esbuild-870e

Conversation

@linear-code

@linear-code linear-code Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1371

Note: This duplicates #1337, which fixes the same advisory for the duplicate Linear issue SOU-1364. SOU-1371 is restricted to its own branch by tooling, so it can't be linked onto #1337 directly. Reviewers can close whichever PR they prefer; merging either resolves the advisory.

Refreshes the yarn.lock entry for esbuild from 0.28.0 to 0.28.1 to address GHSA-g7r4-m6w7-qqqr (arbitrary file read via path traversal in the dev server on Windows).

esbuild is already a top-level dependency at ^0.28.0, which already admits the patched 0.28.1 — only the lockfile was stale. No package.json or resolutions change needed. Verified with yarn why esbuild --recursive that all instances now resolve to 0.28.1.

@linear-code linear-code Bot force-pushed the linear/sou-1371-sourcebot-devsourcebot-ghsa-g7r4-m6w7-qqqr-esbuild-870e branch from 53ed47f to da33f27 Compare June 17, 2026 23:14
@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

@brendan-kellam brendan-kellam marked this pull request as ready for review June 17, 2026 23:49
@brendan-kellam brendan-kellam merged commit c6f9b1d into main Jun 17, 2026
9 of 10 checks passed
@brendan-kellam brendan-kellam deleted the linear/sou-1371-sourcebot-devsourcebot-ghsa-g7r4-m6w7-qqqr-esbuild-870e branch June 17, 2026 23:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant