chore(deps): bump js-yaml to 4.3.2 for GHSA-2883-xcg3-v3hh
The dependency-audit job fails on a high-severity advisory: js-yaml 4.0.0-4.3.1 does not limit CPU use for empty merge sources, so maxTotalMergeKeys can be bypassed. 4.3.2 is the patched release. Lockfile only — package.json already allows it at ^4.3.1, and nothing else in the tree moved. `npm audit --omit=dev --audit-level=high` now reports 0 vulnerabilities. homelable-hacs pins js-yaml at ^4.1.1 in frontend-src, inside the same vulnerable range, so it needs the same bump in its own lockfile. ha-relevant: maybe
This commit is contained in:
committed by
Pouzor - Rémy Jardient
parent
71e78b4279
commit
783ca87acd
Generated
+3
-3
@@ -7194,9 +7194,9 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/js-yaml": {
|
||||
"version": "4.3.1",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz",
|
||||
"integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==",
|
||||
"version": "4.3.2",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz",
|
||||
"integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
|
||||
Reference in New Issue
Block a user