Skip to content

chore(deps): update npm dependencies - #150

Open
gorzell wants to merge 2 commits into
mainfrom
gorzell-resolve-security-alerts
Open

chore(deps): update npm dependencies#150
gorzell wants to merge 2 commits into
mainfrom
gorzell-resolve-security-alerts

Conversation

@gorzell

@gorzell gorzell commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Update transitive npm dependency js-yaml from 3.14.2 to 3.15.1
  • Keep the existing @istanbuljs/load-nyc-config dependency path and compatible 3.x API
  • Resolve all npm audit findings

Security alerts resolved

Risk

Low. This is a patch-level lockfile update within the existing ^3.13.1 transitive constraint. It does not change a direct dependency or application code.

No open Dependabot pull requests are superseded.

Generated by the update-deps skill.

Resolve three Dependabot alerts for quadratic CPU denial-of-service vulnerabilities in js-yaml 3.x.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings August 31, 2026 07:31
@gorzell
gorzell requested a review from a team as a code owner August 31, 2026 07:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The valid lockfile-only update remains constraint-compatible and uses verified npm package metadata.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)
  • crates/string-offsets/js/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants