Skip to content

fix(deps): bump js-yaml to 3.15.2 for GHSA-2883-xcg3-v3hh - #39

Open
steve-calvert-glean wants to merge 1 commit into
mainfrom
fix/js-yaml-advisory
Open

steve-calvert-glean wants to merge 1 commit into
mainfrom
fix/js-yaml-advisory

Conversation

@steve-calvert-glean

Copy link
Copy Markdown
Contributor

Bumps js-yaml 3.15.1 → 3.15.2 in the lockfile to clear GHSA-2883-xcg3-v3hh (high severity), which comes in through gray-matter@4.0.3, a production dependency. The new advisory makes npm run audit fail in CI on main and on every open PR (#37, #38).

  • Lockfile-only change (npm audit fix --omit=dev): 3.15.2 is inside gray-matter's ^3.13.1 range, so there's no package.json or code change.
  • npm audit --omit=dev reports 0 vulnerabilities; npm run check passes (204 tests).

@steve-calvert-glean steve-calvert-glean added the bug Something isn't working label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant