Skip to content

deps: bump js-yaml to 4.2.0 to fix Dependabot alerts#6083

Open
arcjet-rei wants to merge 1 commit into
mainfrom
rei/deps/js-yaml
Open

deps: bump js-yaml to 4.2.0 to fix Dependabot alerts#6083
arcjet-rei wants to merge 1 commit into
mainfrom
rei/deps/js-yaml

Conversation

@arcjet-rei

Copy link
Copy Markdown
Contributor

Resolves all open js-yaml Dependabot alerts (GHSA-h67p-54hq-rp68, medium) by bumping the transitive js-yaml dependency from 4.1.14.2.0.

The advisory: js-yaml does not escape/quote special characters in keys when dumping, which can produce invalid or ambiguous YAML output.

Fixed (10 alerts)

js-yaml bumped to 4.2.0 in these example lockfiles:

Example Alert
nestjs #1703
nextjs-app-dir-rate-limit #1704
nextjs-app-dir-validate-email #1705
nextjs-bot-categories #1706
nextjs-decorate #1707
nextjs-ip-details #1708
nextjs-pages-wrap #1709
nextjs-react-hook-form #1710
nextjs-server-actions #1712
remix-express #1723

Lockfile re-lock only — no package.json changes. The only incidental diff is local workspace file: dependency references syncing from 1.4.0 to the current 1.5.0.

🤖 Generated with Claude Code

Bumps the transitive js-yaml dependency from 4.1.1 to 4.2.0 across the
example lockfiles to resolve GHSA-h67p-54hq-rp68 (special characters in
keys are not escaped/quoted when dumping, which can produce invalid or
ambiguous YAML). Affects: nestjs, remix-express, and the nextjs-*
examples.

Lockfile re-lock only; the only incidental changes are the local workspace
`file:` dependency references syncing from 1.4.0 to the current 1.5.0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@arcjet-rei arcjet-rei requested a review from a team as a code owner June 17, 2026 00:43

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟢 Low Risk

Decision: No Action

Rationale: All 10 files in this PR were excluded by path filters. 10 files excluded by ignore paths. No files remaining after filtering — PR skipped entirely.

Notes

10 files excluded by ignore paths. No files remaining after filtering — PR skipped entirely.

Review: 2c7a856b | Powered by Arcjet Review

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​arcjet/​ip@​1.5.0 ⏵ 1.5.000000

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant