chore(deps): Bump peter-evans/create-pull-request from 6 to 8 - #9
Merged
DeepDiver1975 merged 1 commit intoJun 22, 2026
Conversation
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) from 6 to 8. - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@v6...v8) --- updated-dependencies: - dependency-name: peter-evans/create-pull-request dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
DeepDiver1975
deleted the
dependabot/github_actions/peter-evans/create-pull-request-8
branch
June 22, 2026 16:35
5 tasks
DeepDiver1975
added a commit
that referenced
this pull request
Aug 21, 2026
…1) (#99) Three open alerts all concern the same transitive js-yaml 4.x copies, which Antora nests under three of its packages: - js-yaml 4.1.1 -> 4.3.1 in @antora/content-aggregator, @antora/playbook-builder and @antora/ui-loader - #10 high — quadratic CPU consumption in !!omap resolution (CVE-2026-59870 not backported), needs >= 4.3.1 - #9 high — YAML merge-key chains force quadratic CPU, needs >= 4.3.0 - #8 medium — quadratic-complexity DoS in merge key handling via repeated aliases, needs >= 4.2.0 The direct js-yaml dependency is already 5.3.0 and is not in any vulnerable range, so a blanket override is wrong here: it would downgrade the safe 5.x direct dependency to the 4.x legacy line. Two major lines are live at once, so the pin is applied per parent instead, leaving the root dependency at 5.3.0. The three Antora packages declare "js-yaml": "~4.1", which cannot reach 4.3.1, and Antora's latest stable release (3.1.15) is already in use — only 3.2.0 pre-releases exist upstream. Overrides are therefore the only route to the patched version without moving to a pre-release Antora. Verified under Node 22 (the version CI uses; the local default is 18): npm ci, npm run antora (exit 0), npm test (17/17 pass), npm run pagefind. The 29 xref errors in the Antora log are pre-existing content issues on main (stale "next@ocis:ROOT:" targets) and are non-fatal — no failure_level is configured in site.yml. All three alerts are fixable and fixed; none are left without a fix. They remain open until this lands on the default branch. Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps peter-evans/create-pull-request from 6 to 8.
Release notes
Sourced from peter-evans/create-pull-request's releases.
... (truncated)
Commits
5f6978ffix: retry post-creation API calls on 422 eventual consistency errors (#4356)d32e88dbuild(deps-dev): bump the npm group with 3 updates (#4349)8170bccbuild(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#4344)0041819build(deps): bump picomatch (#4339)b993918build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (#4334)36d7c84build(deps-dev): bump undici from 6.23.0 to 6.24.0 (#4328)a45d1fbbuild(deps): bump@tootallnate/onceand jest-environment-jsdom (#4323)3499eb6build(deps): bump the github-actions group with 2 updates (#4316)3f3b473build(deps): bump minimatch (#4311)6699836build(deps-dev): bump the npm group with 2 updates (#4305)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)