Skip to content

Update js-yaml to 3.14.2#5

Merged
antonk52 merged 2 commits intomasterfrom
copilot/update-js-yaml-dependency
Feb 10, 2026
Merged

Update js-yaml to 3.14.2#5
antonk52 merged 2 commits intomasterfrom
copilot/update-js-yaml-dependency

Conversation

Copy link
Contributor

Copilot AI commented Feb 10, 2026

Resolves moderate severity prototype pollution vulnerability (GHSA-mh29-5h37-fv8m) in js-yaml < 3.14.2.

Changes

  • package-lock.json: js-yaml 3.14.0 → 3.14.2

Transitive dependency of gray-matter and front-matter. Both specify ^3.13.1 which permits this update.


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Co-authored-by: antonk52 <5817809+antonk52@users.noreply.github.com>
Copilot AI changed the title [WIP] Update js-yaml dependency to 3.14.2 or greater Update js-yaml to 3.14.2 to fix prototype pollution vulnerability Feb 10, 2026
Copilot AI requested a review from antonk52 February 10, 2026 21:06
Copilot AI changed the title Update js-yaml to 3.14.2 to fix prototype pollution vulnerability Update js-yaml to 3.14.2 Feb 10, 2026
@antonk52 antonk52 marked this pull request as ready for review February 10, 2026 21:18
@antonk52 antonk52 merged commit d4734b9 into master Feb 10, 2026
1 of 5 checks passed
@antonk52 antonk52 deleted the copilot/update-js-yaml-dependency branch February 10, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants