Skip to content

Bump svgo to 3.3.3 to address CVE-2026-29074 (#1920)#1920

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D96742846
Closed

Bump svgo to 3.3.3 to address CVE-2026-29074 (#1920)#1920
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D96742846

Conversation

@rozele

@rozele rozele commented Mar 16, 2026

Copy link
Copy Markdown
Contributor

Summary:

Adds a Yarn resolution to pin svgo to version 3.3.3 across all transitive dependencies in the Yoga package. This addresses CVE-2026-29074 (GHSA-xpqw-6gx7-v673) by upgrading from 3.3.2 to the patched version. The fix is minimal and safe — no code changes, just a version bump of a transitive dependency used by svgr/plugin-svgo and postcss-svgo.


AI generated Summary & Test Plan from DEV112213693

Reviewed By: NickGerleman

Differential Revision: D96742846

@vercel

vercel Bot commented Mar 16, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
yoga-website Ready Ready Preview, Comment Mar 16, 2026 11:45pm

Request Review

@meta-cla meta-cla Bot added the CLA Signed label Mar 16, 2026
@meta-codesync

meta-codesync Bot commented Mar 16, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D96742846.

@meta-codesync meta-codesync Bot changed the title Bump svgo to 3.3.3 to address CVE-2026-29074 Bump svgo to 3.3.3 to address CVE-2026-29074 (#1920) Mar 16, 2026
rozele added a commit to rozele/yoga that referenced this pull request Mar 16, 2026
Summary:

Adds a Yarn resolution to pin `svgo` to version `3.3.3` across all transitive dependencies in the Yoga package. This addresses CVE-2026-29074 (GHSA-xpqw-6gx7-v673) by upgrading from `3.3.2` to the patched version. The fix is minimal and safe — no code changes, just a version bump of a transitive dependency used by `svgr/plugin-svgo` and `postcss-svgo`.

---
AI generated Summary & Test Plan from DEV112213693

Reviewed By: NickGerleman

Differential Revision: D96742846
@rozele rozele force-pushed the export-D96742846 branch from 80dbc46 to 83e8e0f Compare March 16, 2026 23:02
rozele added a commit to rozele/yoga that referenced this pull request Mar 16, 2026
Summary:
Pull Request resolved: react#1920

Adds a Yarn resolution to pin `svgo` to version `3.3.3` across all transitive dependencies in the Yoga package. This addresses CVE-2026-29074 (GHSA-xpqw-6gx7-v673) by upgrading from `3.3.2` to the patched version. The fix is minimal and safe — no code changes, just a version bump of a transitive dependency used by `svgr/plugin-svgo` and `postcss-svgo`.

 ---
AI generated Summary & Test Plan from DEV112213693

Reviewed By: NickGerleman

Differential Revision: D96742846
@rozele rozele force-pushed the export-D96742846 branch from 83e8e0f to 4c3683b Compare March 16, 2026 23:06
Summary:

Adds a Yarn resolution to pin `svgo` to version `3.3.3` across all transitive dependencies in the Yoga package. This addresses CVE-2026-29074 (GHSA-xpqw-6gx7-v673) by upgrading from `3.3.2` to the patched version. The fix is minimal and safe — no code changes, just a version bump of a transitive dependency used by `svgr/plugin-svgo` and `postcss-svgo`.

---
AI generated Summary & Test Plan from DEV112213693

Reviewed By: NickGerleman

Differential Revision: D96742846
@meta-codesync

meta-codesync Bot commented Mar 17, 2026

Copy link
Copy Markdown

This pull request has been merged in 0a2398d.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant