fix: upgrade adm-zip to 0.6.0 (CVE-2026-39244) - #644
Open
anupamme wants to merge 146 commits into
Open
Conversation
Bumps [cssnano-preset-advanced](https://github.com/cssnano/cssnano) from 7.0.12 to 7.0.13. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.0.13) --- updated-dependencies: - dependency-name: cssnano-preset-advanced dependency-version: 7.0.13 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [globals](https://github.com/sindresorhus/globals) from 17.4.0 to 17.5.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.4.0...v17.5.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.5.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
ci: update Install Dart Sass step to use direct binary download
…rn/cssnano-preset-advanced-7.0.13 build(deps): bump cssnano-preset-advanced from 7.0.12 to 7.0.13
Bumps [stylelint](https://github.com/stylelint/stylelint) from 17.6.0 to 17.7.0. - [Release notes](https://github.com/stylelint/stylelint/releases) - [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md) - [Commits](stylelint/stylelint@17.6.0...17.7.0) --- updated-dependencies: - dependency-name: stylelint dependency-version: 17.7.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.5.0 build(deps-dev): bump globals from 17.4.0 to 17.5.0
Bumps [hugo-extended](https://github.com/jakejarvis/hugo-extended) from 0.159.2 to 0.160.1. - [Commits](jakejarvis/hugo-extended@v0.159.2...v0.160.1) --- updated-dependencies: - dependency-name: hugo-extended dependency-version: 0.160.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/stylelint-17.7.0 build(deps-dev): bump stylelint from 17.6.0 to 17.7.0
…rn/hugo-extended-0.160.1 build(deps): bump hugo-extended from 0.159.2 to 0.160.1
Bumps [eslint](https://github.com/eslint/eslint) from 10.1.0 to 10.2.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.1.0...v10.2.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Update Hugo module dependencies
…rn/eslint-10.2.0 build(deps-dev): bump eslint from 10.1.0 to 10.2.0
Bumps [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) from 0.22.0 to 0.22.1. - [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md) - [Commits](DavidAnson/markdownlint-cli2@v0.22.0...v0.22.1) --- updated-dependencies: - dependency-name: markdownlint-cli2 dependency-version: 0.22.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [gethinode/create-pull-request](https://github.com/gethinode/create-pull-request) from 7 to 8. - [Release notes](https://github.com/gethinode/create-pull-request/releases) - [Commits](gethinode/create-pull-request@v7...v8) --- updated-dependencies: - dependency-name: gethinode/create-pull-request dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
…ions/gethinode/create-pull-request-8 build(deps): bump gethinode/create-pull-request from 7 to 8
…rn/markdownlint-cli2-0.22.1 build(deps-dev): bump markdownlint-cli2 from 0.22.0 to 0.22.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 7.1.4 to 7.1.9. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.1.9) --- updated-dependencies: - dependency-name: cssnano dependency-version: 7.1.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-7.1.7 build(deps): bump cssnano from 7.1.4 to 7.1.9
Bumps [eslint](https://github.com/eslint/eslint) from 10.2.0 to 10.3.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.2.0...v10.3.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.2.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [cssnano-preset-advanced](https://github.com/cssnano/cssnano) from 7.0.13 to 7.0.16. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.0.16) --- updated-dependencies: - dependency-name: cssnano-preset-advanced dependency-version: 7.0.15 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
Update Hugo module dependencies
Bumps [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) from 0.23.0 to 0.23.2. - [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md) - [Commits](DavidAnson/markdownlint-cli2@v0.23.0...v0.23.2) --- updated-dependencies: - dependency-name: markdownlint-cli2 dependency-version: 0.23.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/markdownlint-cli2-0.23.2 build(deps-dev): bump markdownlint-cli2 from 0.23.0 to 0.23.2
Bumps [globals](https://github.com/sindresorhus/globals) from 17.6.0 to 17.8.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.6.0...v17.8.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.8.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.8.0 build(deps-dev): bump globals from 17.6.0 to 17.8.0
Bumps [stylelint](https://github.com/stylelint/stylelint) from 17.14.0 to 17.14.1. - [Release notes](https://github.com/stylelint/stylelint/releases) - [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md) - [Commits](stylelint/stylelint@17.14.0...17.14.1) --- updated-dependencies: - dependency-name: stylelint dependency-version: 17.14.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/stylelint-17.14.1 build(deps-dev): bump stylelint from 17.14.0 to 17.14.1
Update Hugo module dependencies
Bumps [globals](https://github.com/sindresorhus/globals) from 17.8.0 to 17.9.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.8.0...v17.9.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.9.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.9.0 build(deps-dev): bump globals from 17.8.0 to 17.9.0
Update Hugo module dependencies
A cache key suffixed with github.run_id writes a brand-new entry every run and never reclaims the previous one. A repository's Actions cache is a single ~10 GB LRU pool shared by every workflow in it, so those entries fill the pool and GitHub evicts by last access — taking out the smallest, least recently read caches rather than the ones causing the pressure. Replace the suffix with an ISO year-week, which caps each key prefix at roughly two live entries per branch while still saving a fresh snapshot (an exact-key hit makes actions/cache skip the save, so a fully static key would freeze the cache at its first-ever content). restore-keys is unchanged, so the first run after this lands still restores from the previous entry — no cold start. %G/%V are the ISO year and week and must be paired; %Y/%V is wrong across a year boundary. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
ci: bound the Hugo cache key to an ISO week
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.3.1. - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md) - [Commits](nodeca/js-yaml@4.1.1...4.3.1) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/js-yaml-4.3.1 build(deps-dev): bump js-yaml from 4.1.1 to 4.3.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.2 to 8.0.4. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.4) --- updated-dependencies: - dependency-name: cssnano dependency-version: 8.0.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.4 build(deps): bump cssnano from 8.0.2 to 8.0.4
Bumps [eslint](https://github.com/eslint/eslint) from 10.8.0 to 10.8.1. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.0...v10.8.1) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.8.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/eslint-10.8.1 build(deps-dev): bump eslint from 10.8.0 to 10.8.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.4 to 8.0.5. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.5) --- updated-dependencies: - dependency-name: cssnano dependency-version: 8.0.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.5 build(deps): bump cssnano from 8.0.4 to 8.0.5
Bumps [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) from 21.2.1 to 21.2.2. - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.2/@commitlint/cli) --- updated-dependencies: - dependency-name: "@commitlint/cli" dependency-version: 21.2.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/commitlint/cli-21.2.2 build(deps-dev): bump @commitlint/cli from 21.2.1 to 21.2.2
Bumps [globals](https://github.com/sindresorhus/globals) from 17.9.0 to 17.11.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.9.0...v17.11.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.11.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.11.0 build(deps-dev): bump globals from 17.9.0 to 17.11.0
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.5 to 8.0.6. - [Release notes](https://github.com/cssnano/cssnano/releases) - [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.6) --- updated-dependencies: - dependency-name: cssnano dependency-version: 8.0.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.6 build(deps): bump cssnano from 8.0.5 to 8.0.6
Automated dependency upgrade by OrbisAI Security
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrade adm-zip from 0.5.17 to 0.6.0 to fix CVE-2026-39244.
Vulnerability
CVE-2026-39244package-lock.json(dependency:adm-zip)Description: adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation
Evidence
Scanner confirmation: trivy rule
CVE-2026-39244flagged this pattern.Changes
package.jsonpackage-lock.jsonBehavior Preservation
The change is scoped to 2 files on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.
This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.
Automated security fix by OrbisAI Security