Skip to content

chore(deps): update js-yaml to 3.15.1 - #151

Merged
tclem merged 1 commit into
mainfrom
tclem/fix-js-yaml-alerts
Aug 31, 2026
Merged

chore(deps): update js-yaml to 3.15.1#151
tclem merged 1 commit into
mainfrom
tclem/fix-js-yaml-alerts

Conversation

@tclem

@tclem tclem commented Aug 31, 2026

Copy link
Copy Markdown
Member

Pins the development-only transitive js-yaml dependency from 3.14.2 to 3.15.1 so one patch closes three CPU-denial-of-service findings without a manifest or code change.

Dependency path: jest@30.4.2 > @jest/core@30.4.2 > @jest/transform@30.4.1 > babel-plugin-istanbul@7.0.1 > @istanbuljs/load-nyc-config@1.1.0 > js-yaml@3.15.1.

This is a transitive patch update with no major-version or wide-blast-radius dependency risk. No open Dependabot PR is superseded. Generated by the update-deps skill.

  Generated via Copilot (GPT-5.6 Sol) on behalf of @tclem

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0cf91c40-0d1b-4d8d-ad7e-ccadd6712e12
@tclem
tclem marked this pull request as ready for review August 31, 2026 17:03
Copilot AI balanced review requested due to automatic review settings August 31, 2026 17:03
@tclem
tclem requested a review from a team as a code owner August 31, 2026 17:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The verified patch-level lockfile update is internally consistent and resolves the cited vulnerable version ranges.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)
  • crates/string-offsets/js/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@tclem
tclem merged commit 41d51ab into main Aug 31, 2026
5 of 8 checks passed
@tclem
tclem deleted the tclem/fix-js-yaml-alerts branch August 31, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants