Skip to content

Update npm package js-yaml to v5 [SECURITY] - #9879

Open
hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-js-yaml-vulnerability
Open

hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-js-yaml-vulnerability

Conversation

@hash-dependencies

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
js-yaml 4.3.2 → 5.4.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

GHSA-r3ph-w7gj-g6xm

More information

Details

Summary

maxTotalMergeKeys does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.

Example
arr: &arr [{}, {}, {}, ...] # N empty mappings
targets:
  - <<: *arr                # repeated K times

For every target, the loader iterates all N elements of arr. This results in O(N * K) work while totalMergeKeys remains unchanged.

PoC
import { performance } from 'node:perf_hooks'
import { load, YAML11_SCHEMA } from 'js-yaml'

const n = 20000

const src =
  'arr: &arr [' + '{},'.repeat(n).slice(0, -1) + ']\n' +
  'targets:\n' +
  '  - <<: *arr\n'.repeat(n)

const started = performance.now()

load(src, { schema: YAML11_SCHEMA })

console.log(`${(performance.now() - started).toFixed(1)} ms`)

Observed results:

N YAML size Time
800 ~13 KB ~20 ms
3200 ~50 KB ~180 ms
20000 ~500 KB ~13 s
Impact

When merge keys are enabled, an attacker can submit a relatively small YAML document that causes prolonged CPU consumption despite the default maxTotalMergeKeys limit.

Fix

Count every merge source mapping as one budget unit in addition to counting its keys.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nodeca/js-yaml (js-yaml)

v5.4.1

Compare Source

Changed
  • Hard-limit merge sequence size to 100.
Security
  • Count empty mappings in merge sequences toward maxTotalMergeKeys to limit
    CPU usage, #​797.

v5.4.0

Compare Source

Added
  • Added the scalarStyleRules dumper option to customize string formatting.
    See Scalar styling for details.
Changed
  • [breaking] Flattened the low-level AST node style representation. Scalar
    and collection nodes now use SCALAR_STYLE and COLLECTION_STYLE values;
    explicit tags use the separate tagged property. Alias nodes now contain
    only kind and anchor. This only affects code that directly constructs or
    edits AST nodes.
  • [breaking] The sortKeys option was rewritten using AST mutation to avoid
    side effects.
  • Reworked scalar style selection. This can change formatting without changing
    loaded values; in particular, whitespace-only strings are now double-quoted.
Fixed
  • Accept a byte order mark at the start of each document in a stream, #​791.
  • Produce valid flow mappings with quoteFlowKeys and flowSkipColonSpace,
    including alias and property-only keys, #​786.
  • Preserve empty scalar items when converting block sequences to flow style.
  • Do not apply the 1024-character simple-key limit to flow mapping keys.
  • Count Unicode code points, rather than UTF-16 code units, for the
    1024-character simple-key limit.
  • Add an explicit document-end marker after keep-chomped block scalars when
    needed to preserve trailing newlines.

v5.3.0

Compare Source

This release focuses on reworking the documentation and making small
architectural improvements before moving forward.

Added
  • Added completely new documentation.
  • Exported DUMP_SCHEMA, the default schema used by the dumper.
  • Added YAMLException.throwAt() for throwing an error at a source position.
Changed
  • Changed flat constant exports to grouped exports: EVENT_ID, SCALAR_STYLE,
    COLLECTION_STYLE, and CHOMPING_MODE, along with their value types. The old
    exports are still preserved, but deprecated.
  • Made identify mandatory for custom tag definitions. Use
    identify: () => false for load-only tags.
Deprecated
  • Deprecated flat constant exports. Use grouped ones instead.
Removed
  • Removed the MERGE_KEY export (not used anymore after last fixes).
Fixed
  • Validate << sequence items at merge time, so aliased merge sources are
    checked too.
  • Resolve << outside of a mapping key as the plain string '<<', matching
    v4, instead of leaking an internal symbol into the result.

v5.2.3

Compare Source

Fixed
  • Prevent prototype fallback when resolving tags and mapping entries, #​782.
  • Resolve !!timestamp years 0000-0099 correctly, #​775.
  • Preserve implicit null mapping values before document markers and reject
    unpaired mapping event streams, #​784.
  • Preserve folded scalar values with tab-indented lines when round-tripping a
    parsed AST through present(); dump() and loading are unaffected, #​780.

v5.2.2

Compare Source

Fixed
  • Quote flow scalars where a colon precedes a flow indicator, #​773.
Security
  • Avoid exponential parsing time for nested flow sequence pairs.

v5.2.1

Compare Source

Fixed
  • Add Map support to !!omap (should work when realMapTag used)
Security
  • Remove quadratic complexity from !!omap addItem. Regression from v5
    (usually not critical, because YAML11_SCHEMA is not default anymore).

v5.2.0

Compare Source

Added
  • Added maxTotalMergeKeys (10000) loader option to limit the total number of
    keys processed by YAML merge (<<) across one load() / loadAll() call.
  • Added maxAliases (-1) loader option to limit the number of YAML aliases per
    document.
Removed
  • maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge
    processing.
Fixed
  • Round-trip of integers with exponential form (>= 1e21)

v5.1.0

Compare Source

Added
  • Collection tags can finalize an incrementally populated carrier into a
    different result value.
Changed
  • [breaking] quoteStyle now selects the preferred quote style; use the
    restored forceQuotes option to force quoting non-key strings.

v5.0.0

Compare Source

Added
  • Added named exports for schemas, tags, parser events and AST utilities.
  • Reworked JSON_SCHEMA and CORE_SCHEMA with spec-compliant scalar resolution
    rules, and added YAML11_SCHEMA.
  • Added realMapTag for lossless mappings with non-string and complex keys.
    Object-based mappings now reject complex keys instead of stringifying them.
  • Added dump() transform option for changing the generated AST before
    rendering.
  • Added dump() options seqInlineFirst, flowBracketPadding,
    flowSkipCommaSpace, flowSkipColonSpace, quoteFlowKeys, quoteStyle and
    tagBeforeAnchor.
  • Added formal data layers (events and AST) for modular data pipelines.
    • Added low-level parser (to events), presenter and visitor APIs.
  • Added the YAML Test Suite to the
    test set.
Changed
  • See the migration guide for upgrade notes.
  • Rewritten in TypeScript and reorganized the public API around flat named
    exports.
  • Reduced the set of exported schemas:
    • YAML 1.2 schemas: CORE_SCHEMA (loader default), JSON_SCHEMA,
      FAILSAFE_SCHEMA.
    • YAML11_SCHEMA, a combination of all YAML 1.1 tags (YAML 1.1 does not
      specify a schema, only "types").
  • load/dump default behaviour is now specified exactly via schemas:
    • load uses CORE_SCHEMA, without !!merge by default.
    • dump uses YAML11_SCHEMA + CORE_SCHEMA for the quoting check, to
      guarantee backward compatibility by default.
  • !!set is now loaded as a JavaScript Set.
  • Replaced the Type API with a tags API. Similar, but more precise and
    simpler. See examples for details. Tags can be defined via
    defineScalarTag(), defineSequenceTag() and defineMappingTag(), or as a
    spread + override of an existing tag.
  • Renamed Schema.extend() to Schema.withTags().
  • Expanded YAML 1.2 conformance and improved handling of directives, document
    markers, block keys, multiline scalars, tag syntax and other things.
  • load() now throws on empty input instead of returning undefined.
  • Moved browser builds to the js-yaml/browser export.
  • Deprecated the loadAll signature with an iterator (still works, but is a
    candidate for removal).
Removed
  • Removed deprecated safeLoad(), safeLoadAll() and safeDump() exports.
  • Removed DEFAULT_SCHEMA and the nested types export.
  • Removed loader options onWarning, legacy and listener.
  • Removed dumper options styles, replacer, noCompatMode, condenseFlow,
    quotingType and forceQuotes. Renamed noArrayIndent to seqNoIndent.
    Formatting and representation are now configured through presenter options,
    schemas and tag definitions. See migration guide on how to replace.
  • Removed support for importing internal files from lib/.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • "before 4am every weekday,every weekend"

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hash Error Error Sep 30, 2026 3:28am UTC
hashdotdesign-tokens Ready Ready Preview Sep 30, 2026 3:28am UTC
petrinaut Error Error Sep 30, 2026 3:28am UTC
petrinaut-docs Ready Ready Preview Sep 30, 2026 3:28am UTC

Request Review

@cursor

cursor Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Major-version YAML parser upgrade without code changes may alter parse/dump semantics wherever untrusted or merge-heavy YAML is loaded; security fix targets CPU abuse via merge keys.

Overview
Bumps js-yaml from 4.3.2 to 5.4.1 across the monorepo to address GHSA-r3ph-w7gj-g6xm (merge-key handling could burn CPU without respecting maxTotalMergeKeys).

Direct dependency pins change in @apps/hash-api, @hashintel/petrinaut-core, @local/petrinaut-arch-docs, @local/repo-chores, and @tests/hash-playwright, with matching yarn.lock updates. The root resolutions entry for @redocly/openapi-core/js-yaml is aligned to 5.4.1 so transitive OpenAPI tooling picks up the same version.

There are no application source changes in this diff—only lockfile/manifest updates. Because v5 is a major release with loader/dumper and default-schema changes, behavior of existing load/dump usage (e.g. in hash-api email tooling, petrinaut document format, arch-docs frontmatter, repo chores) should be validated via tests rather than assumed drop-in compatible.

Reviewed by Cursor Bugbot for commit 52b6c3e. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot added area/deps Relates to third-party dependencies (area) area/apps > hash* Affects HASH (a `hash-*` app) area/apps > hash-api Affects the HASH API (app) area/libs Relates to first-party libraries/crates/packages (area) type/eng > frontend Owned by the @frontend team type/eng > backend Owned by the @backend team area/tests New or updated tests area/tests > playwright New or updated Playwright tests area/apps labels Sep 30, 2026
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 65.90%. Comparing base (5ab67f8) to head (52b6c3e).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #9879   +/-   ##
=======================================
  Coverage   65.90%   65.90%           
=======================================
  Files        1906     1906           
  Lines      209994   209994           
  Branches     8221     8221           
=======================================
+ Hits       138389   138391    +2     
+ Misses      70053    70051    -2     
  Partials     1552     1552           
Flag Coverage Δ
antsi 1.96% <ø> (ø)
apps.hash-ai-worker-ts 2.04% <ø> (ø)
blockprotocol.type-system 38.15% <ø> (ø)
error-stack 90.55% <ø> (ø)
harpc-codec 84.61% <ø> (ø)
harpc-net 96.30% <ø> (+0.04%) ⬆️
harpc-tower 67.11% <ø> (ø)
harpc-types 0.00% <ø> (ø)
harpc-wire-protocol 93.85% <ø> (ø)
hash-codec 72.09% <ø> (ø)
hash-config 83.57% <ø> (ø)
hash-graph 14.11% <ø> (ø)
hash-graph-api 33.18% <ø> (ø)
hash-graph-atlas 80.01% <ø> (ø)
hash-graph-authentication 97.34% <ø> (ø)
hash-graph-authorization 67.68% <ø> (ø)
hash-graph-embeddings 91.54% <ø> (ø)
hash-graph-postgres-store 31.94% <ø> (ø)
hash-graph-store 51.71% <ø> (ø)
hash-graph-temporal-versioning 50.53% <ø> (ø)
hash-graph-types 0.00% <ø> (ø)
hash-graph-validation 85.37% <ø> (ø)
hash-middleware 88.93% <ø> (ø)
hashql-ast 90.01% <ø> (ø)
hashql-compiletest 28.71% <ø> (ø)
hashql-core 81.41% <ø> (ø)
hashql-diagnostics 72.85% <ø> (ø)
hashql-eval 79.77% <ø> (ø)
hashql-hir 89.10% <ø> (ø)
hashql-mir 87.22% <ø> (ø)
hashql-syntax-jexpr 94.77% <ø> (ø)
local.claude-hooks 0.00% <ø> (ø)
local.harpc-client 51.49% <ø> (ø)
local.hash-backend-utils 3.27% <ø> (ø)
local.hash-graph-sdk 10.02% <ø> (ø)
local.hash-isomorphic-utils 12.22% <ø> (ø)
problematic 89.25% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 52b6c3e. Configure here.

Comment thread package.json
"@pandacss/plugin-lightningcss/browserslist": "^4.28.7",
"@playwright/test": "1.58.2",
"@redocly/openapi-core/js-yaml": "4.3.2",
"@redocly/openapi-core/js-yaml": "5.4.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Redocly forced onto incompatible yaml

High Severity

The @redocly/openapi-core/js-yaml resolution now pins js-yaml 5.4.1 under @redocly/openapi-core 1.34.17, which still depends on js-yaml 4.x APIs (types.*, Schema.extend). That package will fail to initialize, breaking openapi-typescript codegen.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 52b6c3e. Configure here.

@codspeed

codspeed Bot commented Sep 30, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

⚠️ 6 benchmarks measured no execution time

Nothing ran under measurement, usually because the compiler removed the code under test. These results are not comparable, so they count as unchanged.

Preventing compiler optimizations

✅ 98 untouched benchmarks

Performance Changes

Benchmark BASE HEAD Efficiency
⚠️ as_constant < 1 ns < 1 ns N/A
⚠️ constant_equal < 1 ns < 1 ns N/A
⚠️ constant_not_equal < 1 ns < 1 ns N/A
⚠️ access < 1 ns < 1 ns N/A
⚠️ runtime_equal < 1 ns < 1 ns N/A
⚠️ runtime_not_equal < 1 ns < 1 ns N/A

Comparing deps/js/npm-js-yaml-vulnerability (52b6c3e) with main (ca4caf0)

Open in CodSpeed

@github-actions

Copy link
Copy Markdown
Contributor

Benchmark results

hash-graph-benches – Integrations

policy_resolution_large

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2002 $$29.5 \mathrm{ms} \pm 301 \mathrm{μs}\left({\color{gray}0.308 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.84 \mathrm{ms} \pm 34.9 \mathrm{μs}\left({\color{red}7.85 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 1002 $$14.9 \mathrm{ms} \pm 149 \mathrm{μs}\left({\color{red}7.26 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 3314 $$47.0 \mathrm{ms} \pm 448 \mathrm{μs}\left({\color{gray}3.18 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$15.8 \mathrm{ms} \pm 159 \mathrm{μs}\left({\color{red}7.94 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 1527 $$26.6 \mathrm{ms} \pm 320 \mathrm{μs}\left({\color{gray}0.915 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 2078 $$30.6 \mathrm{ms} \pm 291 \mathrm{μs}\left({\color{gray}0.534 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$4.13 \mathrm{ms} \pm 39.7 \mathrm{μs}\left({\color{red}6.90 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 1033 $$15.9 \mathrm{ms} \pm 166 \mathrm{μs}\left({\color{red}7.41 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_medium

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 102 $$4.41 \mathrm{ms} \pm 34.1 \mathrm{μs}\left({\color{red}13.6 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.40 \mathrm{ms} \pm 29.2 \mathrm{μs}\left({\color{red}12.2 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 52 $$3.97 \mathrm{ms} \pm 39.1 \mathrm{μs}\left({\color{red}15.2 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 269 $$6.05 \mathrm{ms} \pm 65.4 \mathrm{μs}\left({\color{red}13.8 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$4.02 \mathrm{ms} \pm 33.4 \mathrm{μs}\left({\color{red}9.33 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 108 $$4.87 \mathrm{ms} \pm 52.6 \mathrm{μs}\left({\color{red}13.1 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 133 $$5.00 \mathrm{ms} \pm 49.0 \mathrm{μs}\left({\color{red}7.32 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$4.00 \mathrm{ms} \pm 36.6 \mathrm{μs}\left({\color{red}13.9 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 63 $$4.81 \mathrm{ms} \pm 51.1 \mathrm{μs}\left({\color{red}11.9 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_none

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2 $$3.07 \mathrm{ms} \pm 24.4 \mathrm{μs}\left({\color{red}9.73 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$2.99 \mathrm{ms} \pm 25.5 \mathrm{μs}\left({\color{red}10.5 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 2 $$3.22 \mathrm{ms} \pm 28.1 \mathrm{μs}\left({\color{red}11.7 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 8 $$3.34 \mathrm{ms} \pm 26.1 \mathrm{μs}\left({\color{red}6.48 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.22 \mathrm{ms} \pm 34.9 \mathrm{μs}\left({\color{red}9.34 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 3 $$3.49 \mathrm{ms} \pm 31.5 \mathrm{μs}\left({\color{red}7.40 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_small

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 52 $$3.29 \mathrm{ms} \pm 34.0 \mathrm{μs}\left({\color{gray}3.74 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.03 \mathrm{ms} \pm 29.8 \mathrm{μs}\left({\color{red}7.25 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 26 $$3.19 \mathrm{ms} \pm 29.6 \mathrm{μs}\left({\color{red}5.40 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 94 $$3.74 \mathrm{ms} \pm 34.2 \mathrm{μs}\left({\color{gray}4.32 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$3.24 \mathrm{ms} \pm 24.9 \mathrm{μs}\left({\color{red}5.18 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 27 $$3.58 \mathrm{ms} \pm 36.7 \mathrm{μs}\left({\color{red}6.88 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 66 $$3.68 \mathrm{ms} \pm 35.5 \mathrm{μs}\left({\color{gray}4.84 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.26 \mathrm{ms} \pm 26.7 \mathrm{μs}\left({\color{red}5.40 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 29 $$3.57 \mathrm{ms} \pm 41.3 \mathrm{μs}\left({\color{gray}4.37 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_complete

Function Value Mean Flame graphs
entity_by_id;one_depth 1 entities $$33.4 \mathrm{ms} \pm 212 \mathrm{μs}\left({\color{gray}1.51 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 10 entities $$73.9 \mathrm{ms} \pm 853 \mathrm{μs}\left({\color{gray}0.755 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 25 entities $$37.5 \mathrm{ms} \pm 405 \mathrm{μs}\left({\color{gray}1.86 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 5 entities $$41.3 \mathrm{ms} \pm 269 \mathrm{μs}\left({\color{gray}0.005 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 50 entities $$44.1 \mathrm{ms} \pm 283 \mathrm{μs}\left({\color{gray}1.15 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 1 entities $$35.2 \mathrm{ms} \pm 244 \mathrm{μs}\left({\color{gray}0.691 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 10 entities $$431 \mathrm{ms} \pm 2.00 \mathrm{ms}\left({\color{gray}0.289 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 25 entities $$96.6 \mathrm{ms} \pm 1.03 \mathrm{ms}\left({\color{gray}1.49 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 5 entities $$82.4 \mathrm{ms} \pm 610 \mathrm{μs}\left({\color{gray}3.12 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 50 entities $$285 \mathrm{ms} \pm 1.42 \mathrm{ms}\left({\color{gray}2.34 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 1 entities $$10.9 \mathrm{ms} \pm 81.2 \mathrm{μs}\left({\color{gray}3.20 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 10 entities $$11.2 \mathrm{ms} \pm 106 \mathrm{μs}\left({\color{gray}4.88 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 25 entities $$11.1 \mathrm{ms} \pm 88.2 \mathrm{μs}\left({\color{gray}0.342 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 5 entities $$11.1 \mathrm{ms} \pm 87.3 \mathrm{μs}\left({\color{gray}4.88 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 50 entities $$11.3 \mathrm{ms} \pm 85.2 \mathrm{μs}\left({\color{red}5.05 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_linkless

Function Value Mean Flame graphs
entity_by_id 1 entities $$11.2 \mathrm{ms} \pm 90.1 \mathrm{μs}\left({\color{gray}4.70 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10 entities $$10.8 \mathrm{ms} \pm 88.2 \mathrm{μs}\left({\color{gray}-1.015 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 100 entities $$11.3 \mathrm{ms} \pm 107 \mathrm{μs}\left({\color{gray}3.95 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 1000 entities $$11.3 \mathrm{ms} \pm 102 \mathrm{μs}\left({\color{gray}3.42 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10000 entities $$11.6 \mathrm{ms} \pm 104 \mathrm{μs}\left({\color{red}7.02 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity

Function Value Mean Flame graphs
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/block/v/1 $$11.3 \mathrm{ms} \pm 93.6 \mathrm{μs}\left({\color{gray}-2.487 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/book/v/1 $$11.4 \mathrm{ms} \pm 90.4 \mathrm{μs}\left({\color{gray}1.54 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/building/v/1 $$11.3 \mathrm{ms} \pm 106 \mathrm{μs}\left({\color{gray}0.986 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/organization/v/1 $$11.5 \mathrm{ms} \pm 83.9 \mathrm{μs}\left({\color{gray}2.89 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/page/v/2 $$11.4 \mathrm{ms} \pm 88.2 \mathrm{μs}\left({\color{gray}2.93 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/person/v/1 $$11.2 \mathrm{ms} \pm 82.2 \mathrm{μs}\left({\color{gray}1.06 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/playlist/v/1 $$11.2 \mathrm{ms} \pm 84.2 \mathrm{μs}\left({\color{gray}1.03 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/song/v/1 $$11.4 \mathrm{ms} \pm 92.7 \mathrm{μs}\left({\color{gray}0.240 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/uk-address/v/1 $$11.5 \mathrm{ms} \pm 76.0 \mathrm{μs}\left({\color{gray}3.10 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity_type

Function Value Mean Flame graphs
get_entity_type_by_id Account ID: bf5a9ef5-dc3b-43cf-a291-6210c0321eba $$8.13 \mathrm{ms} \pm 55.6 \mathrm{μs}\left({\color{gray}0.202 \mathrm{\%}}\right) $$ Flame Graph

representative_read_multiple_entities

Function Value Mean Flame graphs
entity_by_property traversal_paths=0 0 $$58.0 \mathrm{ms} \pm 583 \mathrm{μs}\left({\color{gray}-2.125 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$111 \mathrm{ms} \pm 789 \mathrm{μs}\left({\color{gray}-0.501 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$65.0 \mathrm{ms} \pm 701 \mathrm{μs}\left({\color{gray}-1.079 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$73.8 \mathrm{ms} \pm 666 \mathrm{μs}\left({\color{gray}1.47 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$82.8 \mathrm{ms} \pm 583 \mathrm{μs}\left({\color{gray}-1.554 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$89.9 \mathrm{ms} \pm 645 \mathrm{μs}\left({\color{gray}-1.778 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=0 0 $$46.8 \mathrm{ms} \pm 364 \mathrm{μs}\left({\color{gray}0.559 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$74.9 \mathrm{ms} \pm 671 \mathrm{μs}\left({\color{gray}-0.028 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$52.7 \mathrm{ms} \pm 559 \mathrm{μs}\left({\color{gray}-0.304 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$61.9 \mathrm{ms} \pm 553 \mathrm{μs}\left({\color{gray}1.34 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$65.4 \mathrm{ms} \pm 589 \mathrm{μs}\left({\color{gray}3.39 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$65.5 \mathrm{ms} \pm 573 \mathrm{μs}\left({\color{gray}3.45 \mathrm{\%}}\right) $$

scenarios

Function Value Mean Flame graphs
full_test query-limited $$125 \mathrm{ms} \pm 1.11 \mathrm{ms}\left({\color{red}9.26 \mathrm{\%}}\right) $$ Flame Graph
full_test query-unlimited $$134 \mathrm{ms} \pm 916 \mathrm{μs}\left({\color{red}5.96 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-limited $$19.1 \mathrm{ms} \pm 264 \mathrm{μs}\left({\color{lightgreen}-18.083 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-unlimited $$517 \mathrm{ms} \pm 1.78 \mathrm{ms}\left({\color{gray}-1.446 \mathrm{\%}}\right) $$ Flame Graph

This branch had an error being deployed

2 failed and 3 active deployments
Preview – petrinaut-docs — 52b6c3e9 Deployed Sep 30, 2026 by vercel[bot]
Preview – hashdotdesign-tokens — 52b6c3e9 Deployed Sep 30, 2026 by vercel[bot]
Preview – hash — 52b6c3e9 Deployed Sep 30, 2026 by vercel[bot]
Preview – petrinaut — 52b6c3e9 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/apps > hash* Affects HASH (a `hash-*` app) area/apps > hash-api Affects the HASH API (app) area/apps area/deps Relates to third-party dependencies (area) area/libs Relates to first-party libraries/crates/packages (area) area/tests > playwright New or updated Playwright tests area/tests New or updated tests type/eng > backend Owned by the @backend team type/eng > frontend Owned by the @frontend team

Development

Successfully merging this pull request may close these issues.

0 participants