Skip to content

Update dependency js-yaml to ^3.15.2 - #23

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/js-yaml-3.x
Open

Update dependency js-yaml to ^3.15.2#23
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/js-yaml-3.x

Conversation

@dev-mend-for-github-com

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
js-yaml dependencies minor ^3.14.0^3.15.2

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
High High 7.5 CVE-2026-84375

Release Notes

nodeca/js-yaml (js-yaml)

v3.15.2

Compare Source

v3.15.1

Compare Source

v3.15.0

Compare Source

Security
  • Backported maxTotalMergeKeys option.

v3.14.2

Compare Source

Security
  • Backported v4.1.1 fix to v3

v3.14.1

Compare Source

Security
  • Fix possible code execution in (already unsafe) .load() (in &anchor).

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com Bot added the security fix Security fix generated by Mend label Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants