Skip to content

Bump js-yaml to 4.3.1 for CVE-2026-59870 - #129

Merged
badcuban merged 1 commit into
mainfrom
chore/bump-js-yaml
Aug 8, 2026
Merged

Bump js-yaml to 4.3.1 for CVE-2026-59870#129
badcuban merged 1 commit into
mainfrom
chore/bump-js-yaml

Conversation

@badcuban

@badcuban badcuban commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

Dependabot alert 29 (high): quadratic CPU consumption in js-yaml !!omap resolution, fixed in 4.3.1. Range-scoped override (js-yaml@4 -> 4.3.1) in pnpm-workspace.yaml, matching the existing security-pin pattern there. Lockfile diff is js-yaml only; the astro tree was already on 4.3.1. Runtime consumer is electron-updater parsing latest.yml from our own release feed; electron-builder and astro only see it at build time.

@vercel

vercel Bot commented Aug 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
threadlines Ready Ready Preview Aug 8, 2026 5:43am

Request Review

@github-actions github-actions Bot added size:S vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 8, 2026
@badcuban
badcuban merged commit 3baab1a into main Aug 8, 2026
15 checks passed
@badcuban
badcuban deleted the chore/bump-js-yaml branch August 8, 2026 05:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant