Skip to content

deps: patch Dependabot transitive security advisory for js-yaml - #99

Merged
j-cadena-g merged 1 commit into
mainfrom
deps/js-yaml-4.3.1
Aug 11, 2026
Merged

deps: patch Dependabot transitive security advisory for js-yaml#99
j-cadena-g merged 1 commit into
mainfrom
deps/js-yaml-4.3.1

Conversation

@j-cadena-g

Copy link
Copy Markdown
Owner

Summary

  • Bump the js-yaml pnpm override from 4.3.0 to 4.3.1 to clear Dependabot alert #82 (GHSA-5p4m-2wfm-xmqj / quadratic CPU in !!omap resolution).
  • Refresh pnpm-lock.yaml so eslint/shadcn/markdownlint resolve to the patched release.

Test plan

Bump the pnpm override to 4.3.1 so the lockfile clears GHSA-5p4m-2wfm-xmqj.
@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cadena-sh Ready Ready Preview Aug 11, 2026 8:28pm

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 611fc944-1702-4725-b14f-68515c22e253

📥 Commits

Reviewing files that changed from the base of the PR and between 701ae8f and 47c333a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml
📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: ci
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (actions)
🔇 Additional comments (1)
pnpm-workspace.yaml (1)

12-12: LGTM!


📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated the workspace’s YAML parsing package to version 4.3.1.

Walkthrough

The workspace override for js-yaml changes from version 4.3.0 to 4.3.1.

Changes

Dependency update

Layer / File(s) Summary
Update js-yaml override
pnpm-workspace.yaml
The workspace override now pins js-yaml to version 4.3.1.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

Poem

A rabbit checks the yaml line,
And finds a newer patch in time.
Four-three-one now takes the lead,
The workspace gets the version it needs.
Hop, hop, clean and bright!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the dependency patch and the js-yaml security advisory addressed by the changes.
Description check ✅ Passed The description accurately explains the js-yaml update, security advisory, lockfile refresh, and test results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch deps/js-yaml-4.3.1
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch deps/js-yaml-4.3.1

Comment @coderabbitai help to get the list of available commands.

@j-cadena-g
j-cadena-g merged commit c70b2cc into main Aug 11, 2026
6 of 7 checks passed
@j-cadena-g
j-cadena-g deleted the deps/js-yaml-4.3.1 branch August 11, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant