Skip to content

security: js-yaml ^4.3.1 (dependabot) - #53

Merged
lua-stefan-kruger merged 1 commit into
mainfrom
fix/js-yaml-431-dependabot
Aug 9, 2026
Merged

lua-stefan-kruger merged 1 commit into
mainfrom
fix/js-yaml-431-dependabot

Conversation

@lua-stefan-kruger

Copy link
Copy Markdown
Contributor

Addresses Dependabot alert #29: js-yaml >=4.0.0 <4.3.1.

The nested examples/demo-app/ has its OWN package-lock.json not covered by the root override. Bumped the demo-app override js-yaml@4 from 4.3.0 to ^4.3.1 and regenerated the lockfile surgically (npm install --package-lock-only).

  • Resolved js-yaml: 4.3.1
  • Lockfile diff touches js-yaml only
  • No 3.x js-yaml present; no other nested manifest references js-yaml

🤖 Generated with Claude Code

Bump demo-app override js-yaml@4 from 4.3.0 to ^4.3.1 (resolves 4.3.1)
to address Dependabot alert #29 (js-yaml >=4.0.0 <4.3.1). Nested
examples/demo-app has its own lockfile not covered by the root override.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@lua-stefan-kruger
lua-stefan-kruger merged commit 8816d91 into main Aug 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant