Skip to content

fix: update js-yaml security patch - #28

Merged
kasperrt merged 1 commit into
masterfrom
fix/js-yaml-cve
Aug 12, 2026
Merged

fix: update js-yaml security patch#28
kasperrt merged 1 commit into
masterfrom
fix/js-yaml-cve

Conversation

@kasperrt

@kasperrt kasperrt commented Aug 12, 2026

Copy link
Copy Markdown
Owner

Summary

  • update direct and overridden js-yaml from 4.3.0 to 4.3.1
  • refresh the pnpm lockfile to use the patched release throughout the dependency graph

Why

The previous version is affected by GHSA-5p4m-2wfm-xmqj. The patched release removes the open Dependabot alerts without changing application behavior.

Validation

  • pnpm check
  • pnpm build
  • pnpm audit --audit-level high (no known vulnerabilities)

Merge order

The fixes are independent and may be merged in either order:

  1. fix: update js-yaml security patch #28
  2. fix: update nanoid security patches shottimer#17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant