Skip to content

fix(deps): bump js-yaml to ^4.2.0 to fix CVE-2026-53550#33

Merged
davidkonigsberg merged 2 commits into
mainfrom
dependabot-alert-30-devin
Jun 24, 2026
Merged

fix(deps): bump js-yaml to ^4.2.0 to fix CVE-2026-53550#33
davidkonigsberg merged 2 commits into
mainfrom
dependabot-alert-30-devin

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps the direct dependency js-yaml from ^4.1.1^4.2.0 (resolves to 4.2.0) to fix CVE-2026-53550 (GHSA-h67p-54hq-rp68) — a quadratic-complexity DoS in merge-key handling via repeated aliases.

This is a direct dependency update — no override needed. The dist/index.js bundle is rebuilt via ncc.

Also removes the scaffold file .github/dependabot-alerts/alert-30.md.

@davidkonigsberg ready for review

Link to Devin session: https://app.devin.ai/sessions/f6494f50501747248deaf7f035cdbdd7

github-actions Bot and others added 2 commits June 24, 2026 11:01
@devin-ai-integration devin-ai-integration Bot marked this pull request as ready for review June 24, 2026 11:05
@devin-ai-integration devin-ai-integration Bot changed the title [Dependabot Alert #30] MEDIUM: js-yaml vulnerability fix(deps): bump js-yaml to ^4.2.0 to fix CVE-2026-53550 Jun 24, 2026
@davidkonigsberg davidkonigsberg merged commit 68fe001 into main Jun 24, 2026
1 check passed
@davidkonigsberg davidkonigsberg deleted the dependabot-alert-30-devin branch June 24, 2026 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant