chore(deps): bump js-yaml to 4.3.2 for GHSA-2883-xcg3-v3hh

The dependency-audit job fails on a high-severity advisory: js-yaml 4.0.0-4.3.1
does not limit CPU use for empty merge sources, so maxTotalMergeKeys can be
bypassed. 4.3.2 is the patched release.

Lockfile only — package.json already allows it at ^4.3.1, and nothing else in
the tree moved. `npm audit --omit=dev --audit-level=high` now reports 0
vulnerabilities.

homelable-hacs pins js-yaml at ^4.1.1 in frontend-src, inside the same
vulnerable range, so it needs the same bump in its own lockfile.

ha-relevant: maybe
This commit is contained in:
Pouzor
2026-09-09 01:19:19 +02:00
committed by Pouzor - Rémy Jardient
parent 71e78b4279
commit 783ca87acd
+3 -3
View File
@@ -7194,9 +7194,9 @@
"license": "MIT"
},
"node_modules/js-yaml": {
"version": "4.3.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz",
"integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==",
"version": "4.3.2",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz",
"integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==",
"funding": [
{
"type": "github",