Skip to content

Core: bump serialize-javascript to 7.0.5 via npm override#14715

Open
patmmccann wants to merge 1 commit intomasterfrom
codex/update-serialize-javascript-to-7.0.5+
Open

Core: bump serialize-javascript to 7.0.5 via npm override#14715
patmmccann wants to merge 1 commit intomasterfrom
codex/update-serialize-javascript-to-7.0.5+

Conversation

@patmmccann
Copy link
Copy Markdown
Collaborator

@patmmccann patmmccann commented Apr 13, 2026

resolves two security alerts

Motivation

  • The dependency tree was locking serialize-javascript at 6.0.2, so pinning to a 7.0.5+ release is required to resolve the older, potentially vulnerable version.

Description

  • Added an npm overrides entry in package.json to force serialize-javascript to ^7.0.5 across the dependency graph.【F:package.json†L167-L173】
  • Regenerated package-lock.json so the locked serialize-javascript package resolves to 7.0.5 and updated transitive references (notably under mocha and terser-webpack-plugin).【F:package-lock.json†L18926-L18934】【F:package-lock.json†L32837-L32837】【F:package-lock.json†L35265-L35270】
  • Committed the updated package.json and package-lock.json to lock the new resolution.

Testing

  • Ran npm install --package-lock-only which completed successfully.
  • Verified the lockfile resolution with node -e "const lock=require('./package-lock.json'); console.log(lock.packages['node_modules/serialize-javascript'].version)" which prints 7.0.5.
  • Inspected the dependency graph with npm ls serialize-javascript --all and confirmed the lockfile now resolves serialize-javascript to the overridden ^7.0.5 entry.

Codex Task

@coveralls
Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 24368156231

Coverage decreased (-0.001%) to 96.342%

Details

  • Coverage decreased (-0.001%) from the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • 1 coverage regression across 1 file.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

1 previously-covered line in 1 file lost coverage.

File Lines Losing Coverage Coverage
test/spec/modules/id5AnalyticsAdapter_spec.js 1 96.13%

Coverage Stats

Coverage Status
Relevant Lines: 226519
Covered Lines: 218234
Line Coverage: 96.34%
Relevant Branches: 52776
Covered Branches: 42849
Branch Coverage: 81.19%
Branches in Coverage %: No
Coverage Strength: 72.74 hits per line

💛 - Coveralls

@patmmccann
Copy link
Copy Markdown
Collaborator Author

@copilot resolve the merge conflicts in this pull request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants