Skip to content

Bump js-yaml override to 4.2.0 (Dependabot #359) #2729

@ConnorQi01

Description

@ConnorQi01

Summary

The npm overrides entry for js-yaml is pinned to 4.1.1, which is affected by GHSA-h4hr-7fg3-h35w (Quadratic-complexity DoS via merge-key repeated aliases). The patched version is 4.2.0.

Proposed Changes

  • Bump overrides["js-yaml"] from 4.1.1 to 4.2.0 in package.json
  • Update package-lock.json accordingly

Validation

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions