Skip to content

Bump js-yaml to 4.3.1 and 3.15.1 - #29

Merged
scsmith merged 1 commit into
mainfrom
bump-js-yaml-431
Aug 17, 2026
Merged

Bump js-yaml to 4.3.1 and 3.15.1#29
scsmith merged 1 commit into
mainfrom
bump-js-yaml-431

Conversation

@scsmith

@scsmith scsmith commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Clears both open high-severity Dependabot alerts (GHSA-5p4m-2wfm-xmqj, quadratic CPU consumption in !!omap resolution). The advisory covers both the 3.x and 4.x lines, which is why there were two.

#27 bumped to 4.3.0 the day before 4.3.1 shipped, so this picks up the tail of that, plus the nested 3.x copy under @istanbuljs/load-nyc-config that came in via jest.

Both are devDependencies — eslint and jest — so nothing here reaches consumers of the published package. Lockfile-only, six lines, within the existing ranges. npm audit goes from 1 high to 0.

…5p4m-2wfm-xmqj]

Quadratic CPU consumption in !!omap resolution, affecting both the 3.x and
4.x lines. #27 bumped to 4.3.0 the day before 4.3.1 shipped, so this picks up
the tail of that plus the nested 3.x copy under @istanbuljs/load-nyc-config.

Both are devDependencies (eslint and jest), so nothing reaches consumers of
the published package. Lockfile-only, within the existing ranges.

npm audit goes from 1 high to 0.
@scsmith
scsmith merged commit 798c9b6 into main Aug 17, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant