Skip to content

fix: upgrade adm-zip to 0.6.0 (CVE-2026-39244) - #644

Open
anupamme wants to merge 146 commits into
gethinode:developfrom
anupamme:fix-repo-template-cve-2026-39244-adm-zip
Open

fix: upgrade adm-zip to 0.6.0 (CVE-2026-39244)#644
anupamme wants to merge 146 commits into
gethinode:developfrom
anupamme:fix-repo-template-cve-2026-39244-adm-zip

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Upgrade adm-zip from 0.5.17 to 0.6.0 to fix CVE-2026-39244.

Vulnerability

Field Value
ID CVE-2026-39244
Severity HIGH
Scanner trivy
Rule CVE-2026-39244
File package-lock.json (dependency: adm-zip)
Assessment Present in dependency tree, not confirmed reachable

Description: adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation

Evidence

Scanner confirmation: trivy rule CVE-2026-39244 flagged this pattern.

Changes

  • package.json
  • package-lock.json

Behavior Preservation

The change is scoped to 2 files on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.


This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.


Automated security fix by OrbisAI Security

dependabot Bot and others added 30 commits April 13, 2026 19:57
Bumps [cssnano-preset-advanced](https://github.com/cssnano/cssnano) from 7.0.12 to 7.0.13.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.0.13)

---
updated-dependencies:
- dependency-name: cssnano-preset-advanced
  dependency-version: 7.0.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [globals](https://github.com/sindresorhus/globals) from 17.4.0 to 17.5.0.
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.4.0...v17.5.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
ci: update Install Dart Sass step to use direct binary download
…rn/cssnano-preset-advanced-7.0.13

build(deps): bump cssnano-preset-advanced from 7.0.12 to 7.0.13
Bumps [stylelint](https://github.com/stylelint/stylelint) from 17.6.0 to 17.7.0.
- [Release notes](https://github.com/stylelint/stylelint/releases)
- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)
- [Commits](stylelint/stylelint@17.6.0...17.7.0)

---
updated-dependencies:
- dependency-name: stylelint
  dependency-version: 17.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.5.0

build(deps-dev): bump globals from 17.4.0 to 17.5.0
Bumps [hugo-extended](https://github.com/jakejarvis/hugo-extended) from 0.159.2 to 0.160.1.
- [Commits](jakejarvis/hugo-extended@v0.159.2...v0.160.1)

---
updated-dependencies:
- dependency-name: hugo-extended
  dependency-version: 0.160.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/stylelint-17.7.0

build(deps-dev): bump stylelint from 17.6.0 to 17.7.0
…rn/hugo-extended-0.160.1

build(deps): bump hugo-extended from 0.159.2 to 0.160.1
Bumps [eslint](https://github.com/eslint/eslint) from 10.1.0 to 10.2.0.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.1.0...v10.2.0)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/eslint-10.2.0

build(deps-dev): bump eslint from 10.1.0 to 10.2.0
Bumps [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) from 0.22.0 to 0.22.1.
- [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint-cli2@v0.22.0...v0.22.1)

---
updated-dependencies:
- dependency-name: markdownlint-cli2
  dependency-version: 0.22.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [gethinode/create-pull-request](https://github.com/gethinode/create-pull-request) from 7 to 8.
- [Release notes](https://github.com/gethinode/create-pull-request/releases)
- [Commits](gethinode/create-pull-request@v7...v8)

---
updated-dependencies:
- dependency-name: gethinode/create-pull-request
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
…ions/gethinode/create-pull-request-8

build(deps): bump gethinode/create-pull-request from 7 to 8
…rn/markdownlint-cli2-0.22.1

build(deps-dev): bump markdownlint-cli2 from 0.22.0 to 0.22.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 7.1.4 to 7.1.9.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.1.9)

---
updated-dependencies:
- dependency-name: cssnano
  dependency-version: 7.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-7.1.7

build(deps): bump cssnano from 7.1.4 to 7.1.9
Bumps [eslint](https://github.com/eslint/eslint) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.2.0...v10.3.0)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [cssnano-preset-advanced](https://github.com/cssnano/cssnano) from 7.0.13 to 7.0.16.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@7.0.16)

---
updated-dependencies:
- dependency-name: cssnano-preset-advanced
  dependency-version: 7.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
markdumay and others added 30 commits August 2, 2026 19:01
Bumps [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) from 0.23.0 to 0.23.2.
- [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint-cli2@v0.23.0...v0.23.2)

---
updated-dependencies:
- dependency-name: markdownlint-cli2
  dependency-version: 0.23.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/markdownlint-cli2-0.23.2

build(deps-dev): bump markdownlint-cli2 from 0.23.0 to 0.23.2
Bumps [globals](https://github.com/sindresorhus/globals) from 17.6.0 to 17.8.0.
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.6.0...v17.8.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.8.0

build(deps-dev): bump globals from 17.6.0 to 17.8.0
Bumps [stylelint](https://github.com/stylelint/stylelint) from 17.14.0 to 17.14.1.
- [Release notes](https://github.com/stylelint/stylelint/releases)
- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)
- [Commits](stylelint/stylelint@17.14.0...17.14.1)

---
updated-dependencies:
- dependency-name: stylelint
  dependency-version: 17.14.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/stylelint-17.14.1

build(deps-dev): bump stylelint from 17.14.0 to 17.14.1
Bumps [globals](https://github.com/sindresorhus/globals) from 17.8.0 to 17.9.0.
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.8.0...v17.9.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.9.0

build(deps-dev): bump globals from 17.8.0 to 17.9.0
A cache key suffixed with github.run_id writes a brand-new entry every run and never reclaims the
previous one. A repository's Actions cache is a single ~10 GB LRU pool shared by every workflow in
it, so those entries fill the pool and GitHub evicts by last access — taking out the smallest, least
recently read caches rather than the ones causing the pressure.

Replace the suffix with an ISO year-week, which caps each key prefix at roughly two live entries per
branch while still saving a fresh snapshot (an exact-key hit makes actions/cache skip the save, so a
fully static key would freeze the cache at its first-ever content). restore-keys is unchanged, so
the first run after this lands still restores from the previous entry — no cold start.

%G/%V are the ISO year and week and must be paired; %Y/%V is wrong across a year boundary.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
ci: bound the Hugo cache key to an ISO week
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.1.1...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/js-yaml-4.3.1

build(deps-dev): bump js-yaml from 4.1.1 to 4.3.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.2 to 8.0.4.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.4)

---
updated-dependencies:
- dependency-name: cssnano
  dependency-version: 8.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.4

build(deps): bump cssnano from 8.0.2 to 8.0.4
Bumps [eslint](https://github.com/eslint/eslint) from 10.8.0 to 10.8.1.
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.0...v10.8.1)

---
updated-dependencies:
- dependency-name: eslint
  dependency-version: 10.8.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/eslint-10.8.1

build(deps-dev): bump eslint from 10.8.0 to 10.8.1
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.4 to 8.0.5.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.5)

---
updated-dependencies:
- dependency-name: cssnano
  dependency-version: 8.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.5

build(deps): bump cssnano from 8.0.4 to 8.0.5
Bumps [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) from 21.2.1 to 21.2.2.
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.2/@commitlint/cli)

---
updated-dependencies:
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/commitlint/cli-21.2.2

build(deps-dev): bump @commitlint/cli from 21.2.1 to 21.2.2
Bumps [globals](https://github.com/sindresorhus/globals) from 17.9.0 to 17.11.0.
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.9.0...v17.11.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/globals-17.11.0

build(deps-dev): bump globals from 17.9.0 to 17.11.0
Bumps [cssnano](https://github.com/cssnano/cssnano) from 8.0.5 to 8.0.6.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/[email protected]@8.0.6)

---
updated-dependencies:
- dependency-name: cssnano
  dependency-version: 8.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…rn/cssnano-8.0.6

build(deps): bump cssnano from 8.0.5 to 8.0.6
Automated dependency upgrade by OrbisAI Security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants