From 2c31809ee3b777ce4215db65d0d19cf7312edc17 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 19 Aug 2026 23:24:26 +0000 Subject: [PATCH 1/2] Bump js-yaml from 4.3.1 to 5.3.0 Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 5.3.0. - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...5.3.0) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 5.3.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- package-lock.json | 33 ++++++++++++++++++++++++++++----- package.json | 2 +- 2 files changed, 29 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 35a5b4a..34dcf0a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -28,7 +28,7 @@ "eslint-plugin-jest": "^29.0.1", "eslint-plugin-prettier": "^5.5.4", "jest": "^30.1.3", - "js-yaml": "^4.1.0", + "js-yaml": "^5.3.0", "make-coverage-badge": "^1.2.0", "prettier": "^3.6.2", "rollup": "^4.62.5", @@ -1080,6 +1080,29 @@ "url": "https://opencollective.com/eslint" } }, + "node_modules/@eslint/eslintrc/node_modules/js-yaml": { + "version": "4.3.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", + "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "dev": true, + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/puzrin" + }, + { + "type": "github", + "url": "https://github.com/sponsors/nodeca" + } + ], + "license": "MIT", + "dependencies": { + "argparse": "^2.0.1" + }, + "bin": { + "js-yaml": "bin/js-yaml.js" + } + }, "node_modules/@eslint/js": { "version": "9.39.5", "resolved": "https://registry.npmjs.org/@eslint/js/-/js-9.39.5.tgz", @@ -6550,9 +6573,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", - "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "version": "5.3.0", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.3.0.tgz", + "integrity": "sha512-muutsYr+e2+d3rTgUGslq5rxbBlUy3cJ61IsHag2QNDQV+7zXWjkUpmALIajhrlLlrgRUiymj6U3zUr/TMK84Q==", "dev": true, "funding": [ { @@ -6569,7 +6592,7 @@ "argparse": "^2.0.1" }, "bin": { - "js-yaml": "bin/js-yaml.js" + "js-yaml": "bin/js-yaml.mjs" } }, "node_modules/jsesc": { diff --git a/package.json b/package.json index 3dc87c0..53df4ad 100644 --- a/package.json +++ b/package.json @@ -59,7 +59,7 @@ "eslint-plugin-jest": "^29.0.1", "eslint-plugin-prettier": "^5.5.4", "jest": "^30.1.3", - "js-yaml": "^4.1.0", + "js-yaml": "^5.3.0", "make-coverage-badge": "^1.2.0", "prettier": "^3.6.2", "rollup": "^4.62.5", From 35f114593cdb2d08b0e08063cbcf48f612d1fefd Mon Sep 17 00:00:00 2001 From: Brandon White Date: Tue, 1 Sep 2026 16:05:29 -0500 Subject: [PATCH 2/2] test: import js-yaml load as a named export js-yaml 5 is pure ESM and exposes named exports only, so the previous default import failed with "The requested module 'js-yaml' does not provide an export named 'default'" and main.test.js could not run. Co-Authored-By: Claude Opus 5 --- __tests__/main.test.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/__tests__/main.test.js b/__tests__/main.test.js index d7771b4..a810e32 100644 --- a/__tests__/main.test.js +++ b/__tests__/main.test.js @@ -5,7 +5,7 @@ import { jest } from '@jest/globals' import fs from 'node:fs' import path from 'node:path' import { fileURLToPath } from 'node:url' -import yaml from 'js-yaml' +import { load as loadYaml } from 'js-yaml' import * as core from '../__fixtures__/core.js' @@ -20,7 +20,7 @@ const actionYmlFile = path.join(dirname, '..', 'action.yml') describe('action', () => { const inputsDefaults = {} - const actionYml = yaml.load(fs.readFileSync(actionYmlFile)) + const actionYml = loadYaml(fs.readFileSync(actionYmlFile)) for (const [inputName, inputConfig] of Object.entries(actionYml.inputs)) { inputsDefaults[inputName] = inputConfig.default }