Skip to content

chore(deps): bump js-yaml from 4.3.1 to 4.3.2 in /docs - #2920

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/js-yaml-4.3.2
Open

chore(deps): bump js-yaml from 4.3.1 to 4.3.2 in /docs#2920
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/docs/js-yaml-4.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.1 to 4.3.2.

Changelog

Sourced from js-yaml's changelog.

4.3.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.
Commits

Copilot AI lite review requested due to automatic review settings September 9, 2026 12:34
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a straightforward lockfile-only dependency patch bump with no apparent inconsistencies or leftover references to the prior version.

Pull request overview

Updates the documentation site’s npm lockfile to pull in js-yaml v4.3.2 (from v4.3.1), reflecting the upstream patch release (including merge-sequence limits intended to reduce CPU usage risk).

Changes:

  • Bump node_modules/js-yaml from 4.3.1 to 4.3.2 in the docs lockfile.
  • Update the corresponding tarball resolved URL and integrity hash.
File summaries
File Description
docs/package-lock.json Updates the locked js-yaml package version/resolution to 4.3.2 for the docs workspace.
Review details

Copilot wasn't able to review any files in this pull request.

Files not reviewed (1)

  • docs/package-lock.json: Generated file
  • Files reviewed: 0/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/docs/js-yaml-4.3.2 branch from f46d69b to cd4ccba Compare September 11, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant