Skip to content

security: bump js-yaml to patched versions - #46

Merged
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
security/bump-js-yaml-ghsa-5p4m
Aug 20, 2026
Merged

security: bump js-yaml to patched versions#46
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
security/bump-js-yaml-ghsa-5p4m

Conversation

@jkennedyvz

Copy link
Copy Markdown
Contributor

Summary

  • bump transitive js-yaml 3.x from 3.15.0 to 3.15.1
  • bump transitive js-yaml 4.x from 4.3.0 to 4.3.1
  • resolve Dependabot alerts #53 and #54 for GHSA-5p4m-2wfm-xmqj

Validation

  • yarn install --frozen-lockfile
  • yarn build
  • yarn lint
  • yarn lint:langgraph-json
  • yarn format:check
  • yarn test

Scoped to the vulnerable lockfile entries only.

@jkennedyvz
John Kennedy (jkennedyvz) marked this pull request as ready for review August 20, 2026 07:48
@jkennedyvz
John Kennedy (jkennedyvz) merged commit 6a88668 into main Aug 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant