Skip to content

Update dependency js-yaml to ^3.14.2#67

Open
mend-5034428[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/js-yaml-3.x
Open

Update dependency js-yaml to ^3.14.2#67
mend-5034428[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/js-yaml-3.x

Conversation

@mend-5034428
Copy link

@mend-5034428 mend-5034428 bot commented Oct 17, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
js-yaml ^3.13.1 -> ^3.14.2 age adoption passing confidence

Release Notes

nodeca/js-yaml (js-yaml)

v3.14.2

Compare Source

Security
  • Backported v4.1.1 fix to v3

v3.14.1

Compare Source

Security
  • Fix possible code execution in (already unsafe) .load() (in &anchor).

v3.14.0

Compare Source

Changed
  • Support safe/loadAll(input, options) variant of call.
  • CI: drop outdated nodejs versions.
  • Dev deps bump.
Fixed
  • Quote = in plain scalars #​519.
  • Check the node type for !<?> tag in case user manually specifies it.
  • Verify that there are no null-bytes in input.
  • Fix wrong quote position when writing condensed flow, #​526.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

@mend-5034428 mend-5034428 bot force-pushed the whitesource-remediate/js-yaml-3.x branch from 0707759 to a3cec0d Compare September 2, 2025 01:10
@mend-5034428 mend-5034428 bot changed the title Update dependency js-yaml to ^3.14.1 Update dependency js-yaml to ^3.14.2 Nov 15, 2025
@mend-5034428 mend-5034428 bot force-pushed the whitesource-remediate/js-yaml-3.x branch from a3cec0d to 1fa4a4c Compare November 15, 2025 01:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants