Skip to content

Conversation

@aavshr
Copy link
Collaborator

@aavshr aavshr commented Nov 17, 2025

Changes

  • Bump js-yaml to 3.14.2, 4.1.1 to address CVE.

Currently the CVE database shows only 4.1.1 as patched but the fix was backported to 3.14.2 as well.

@aavshr aavshr force-pushed the aavash/bump-js-yaml branch from 006a65a to ce47508 Compare November 17, 2025 12:25
@aavshr aavshr changed the title chore (deps): bump js-yaml to 3.14.2 through resolutions chore (deps): bump js-yaml to 3.14.2, 4.1.1 through resolutions Nov 17, 2025
@aavshr aavshr merged commit 5637749 into main Nov 17, 2025
2 checks passed
@aavshr aavshr deleted the aavash/bump-js-yaml branch November 17, 2025 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants