Skip to content

Bump js-yaml to 4.3.2 in package-lock.json - #243

Merged
abdulahmad307 merged 1 commit into
mainfrom
copilot/update-js-yaml-4-3-2
Sep 18, 2026
Merged

abdulahmad307 merged 1 commit into
mainfrom
copilot/update-js-yaml-4-3-2

Conversation

Copilot AI commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

js-yaml@4.3.1, a transitive dependency pulled in via @eslint/eslintrc, had a known security vulnerability.

Changes

  • Updated the nested js-yaml entry under node_modules/@eslint/eslintrc/node_modules/js-yaml in package-lock.json from 4.3.1 to 4.3.2, including its resolved URL and integrity hash.

This is a dev-only, transitive dependency — no changes to package.json or application source code were needed. The top-level js-yaml (5.4.2) and the markdownlint-cli2 nested js-yaml@5.2.2 were already on unaffected versions and left unchanged.

Co-authored-by: abdulahmad307 <204748719+abdulahmad307@users.noreply.github.com>
@abdulahmad307

Copy link
Copy Markdown
Contributor

@abdulahmad307
abdulahmad307 marked this pull request as ready for review September 18, 2026 14:14
@abdulahmad307
abdulahmad307 requested a review from a team as a code owner September 18, 2026 14:14
@abdulahmad307
abdulahmad307 requested review from v-joelamyman and a balanced review from Copilot September 18, 2026 14:14

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@abdulahmad307
abdulahmad307 merged commit 17b57b3 into main Sep 18, 2026
6 checks passed
@abdulahmad307
abdulahmad307 deleted the copilot/update-js-yaml-4-3-2 branch September 18, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants