Skip to content

security: pin js-yaml to 4.3.2 - #1290

Merged
michalharakal merged 1 commit into
developfrom
security/js-yaml-4.3.2
Sep 20, 2026
Merged

michalharakal merged 1 commit into
developfrom
security/js-yaml-4.3.2

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Closes Dependabot alert #127GHSA-2883-xcg3-v3hh (high): maxTotalMergeKeys does not limit CPU use for empty merge sources; fixed in js-yaml 4.3.2.

Same mechanism as the existing pin: npm-js-yaml in gradle/libs.versions.toml 4.3.1 → 4.3.2, kotlin-js-store/yarn.lock regenerated with ./gradlew kotlinUpgradeYarnLock kotlinWasmUpgradeYarnLock (only the js-yaml entry changes; the pin is JS-scoped, the Wasm lockfile is untouched). verifyNpmPins green.

JS build/test tooling only — not part of any published artifact.

GHSA-2883-xcg3-v3hh (high): maxTotalMergeKeys does not limit CPU use for empty merge
sources, fixed in 4.3.2. JS build/test tooling only; lockfile regenerated with
kotlinUpgradeYarnLock, verifyNpmPins green.
@michalharakal
michalharakal merged commit 3a8e352 into develop Sep 20, 2026
14 checks passed
@michalharakal michalharakal mentioned this pull request Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant