Skip to content

fix: bump js-yaml resolution to 4.3.0 (dependabot #77)#225

Merged
maximizeIT merged 1 commit into
mainfrom
copilot/fix-dependabot-issue-77
Jul 22, 2026
Merged

fix: bump js-yaml resolution to 4.3.0 (dependabot #77)#225
maximizeIT merged 1 commit into
mainfrom
copilot/fix-dependabot-issue-77

Conversation

Copilot AI commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

js-yaml < 4.3.0 is vulnerable to a ReDoS-style quadratic CPU exhaustion via crafted YAML merge-key chains (GHSA). The yarn resolution was pinned to the vulnerable 4.2.0.

Changes

  • package.json — bumps resolutions["js-yaml"] from 4.2.04.3.0
  • yarn.lock — regenerated; yarn audit now reports 0 vulnerabilities

Copilot AI requested a review from maximizeIT July 22, 2026 08:53
@maximizeIT
maximizeIT marked this pull request as ready for review July 22, 2026 08:53
@maximizeIT
maximizeIT requested a review from a team as a code owner July 22, 2026 08:53
@maximizeIT
maximizeIT requested a review from paulstamandjr July 22, 2026 08:53
@maximizeIT
maximizeIT enabled auto-merge July 22, 2026 08:53
@maximizeIT
maximizeIT merged commit e7449b5 into main Jul 22, 2026
7 checks passed
@maximizeIT
maximizeIT deleted the copilot/fix-dependabot-issue-77 branch July 22, 2026 11:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants