Skip to content

chore(deps): bump js-yaml to 4.3.1 in the node lockfile - #40

Merged
MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/js-yaml-4.3.1
Aug 11, 2026
Merged

chore(deps): bump js-yaml to 4.3.1 in the node lockfile#40
MohammadHaroonAbuomar merged 1 commit into
mainfrom
mhabuomar/js-yaml-4.3.1

Conversation

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Contributor

Closes the open HIGH Dependabot alert (js-yaml quadratic CPU in !!omap resolution; vulnerable range >=4.0.0 <4.3.1). Transitive dev dependency of @napi-rs/cli — build tooling only, no runtime exposure. Lockfile-only change within the existing ^4.2.0 range; node test suite green locally.

Resolves the open Dependabot alert (quadratic CPU consumption in
!!omap resolution, CVE-2026-59870 class): js-yaml is a transitive
dev dependency of @napi-rs/cli, build tooling only; lockfile-only
bump within the existing semver range.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 811d2e2 into main Aug 11, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant