Skip to content

chore: upgrade baseline-browser-mapping to 2.11.21 to address CVE-2026-45819 - #1645

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/baseline-browser-mapping
Sep 10, 2026
Merged

chore: upgrade baseline-browser-mapping to 2.11.21 to address CVE-2026-45819#1645
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/baseline-browser-mapping

Conversation

@claude

@claude claude Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-2202

Refreshes the yarn.lock entries for baseline-browser-mapping, which now dedupe onto 2.11.21.

baseline-browser-mapping is not a direct dependency of any workspace. It arrived twice: through browserslist at ^2.11.12 (already resolving to a patched 2.11.20) and through next at ^2.9.19, which was stale at the affected 2.10.13. Both ranges already admitted the patched release, so this is a lockfile refresh only. No package.json change and no resolutions override were needed.

Advisory addressed

Advisory Patched in Summary
CVE-2026-45819 2.11.0 Calls process.exit() instead of throwing on invalid or conflicting input parameters, allowing immediate process termination

Verification

  • yarn why baseline-browser-mapping reports every instance resolving to baseline-browser-mapping@npm:2.11.21, with 2.10.13 gone from the graph.
  • yarn workspace @sourcebot/web test --run — 140 files, 1440 tests passed.
  • yarn workspace @sourcebot/web build — succeeded. Included because this package feeds browserslist target resolution at build time.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency bump with no application code changes; risk is limited to browserslist/build-time target resolution behavior in the patched package.

Overview
Addresses CVE-2026-45819 (SOU-2202) by refreshing yarn.lock so all transitive baseline-browser-mapping instances resolve to 2.11.21, removing the stale 2.10.13 copy that came in via next while browserslist was already on a newer patch.

There are no package.json or resolution overrides—only lockfile deduplication and a CHANGELOG entry under Unreleased → Fixed.

Reviewed by Cursor Bugbot for commit 8d21806. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Fixes SOU-2202 by upgrading baseline-browser-mapping to 2.11.21 in yarn.lock, addressing CVE-2026-45819. This is a lockfile-only refresh; both browserslist and next already permitted the patched version.

  • yarn why confirms all instances resolve to 2.11.21.
  • Workspace tests and build pass.
  • Adds a changelog entry under Fixed.

Written for commit 8d21806. Summary will update on new commits.

Review in cubic

github-actions Bot and others added 2 commits September 10, 2026 12:42
Refreshes the yarn.lock entries for baseline-browser-mapping. next
requested it at `^2.9.19`, which was stale at 2.10.13; that range already
admitted the patched version, so no manifest change or resolution override
is needed. The two lock entries now dedupe onto 2.11.21.

Addresses CVE-2026-45819.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@claude
claude Bot requested a review from brendan-kellam September 10, 2026 12:42
@github-actions

github-actions Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2173
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.4 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.13 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/codemirror-lang-elixir) LICENSE file, as shipped in the published package; npm registry metadata has no license field
khroma 2.1.0 UNKNOWN MIT GitHub repo (fabiospampinato/khroma) license file, as shipped in the published package; npm registry metadata has no license field
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/lezer-elixir) LICENSE file, as shipped in the published package; npm registry metadata has no license field
map-stream 0.1.0 UNKNOWN MIT GitHub repo (dominictarr/map-stream) LICENCE file, as shipped in the published package; npm registry metadata has no license field
memorystream 0.3.1 UNKNOWN MIT extracted from object (npm registry legacy "licenses" array: {"type":"MIT"}), confirmed against shipped LICENSE file
pause-stream 0.0.11 MIT,Apache2 (MIT OR Apache-2.0) extracted from object (license array ["MIT","Apache2"]), confirmed against shipped LICENSE file: "Dual Licensed MIT and Apache 2"
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 shipped LICENSE file (full Apache License 2.0 text, PostHog/Hiberly Inc.); npm registry reports "SEE LICENSE IN LICENSE"
valid-url 1.0.9 UNKNOWN MIT GitHub repo (ogt/valid-url) LICENSE file, as shipped in the published package; npm registry metadata has no license field

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: cc3397b7-601b-4897-b246-6be147486c0b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@brendan-kellam
brendan-kellam merged commit d2ebcfd into main Sep 10, 2026
12 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/baseline-browser-mapping branch September 10, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant