From 783ca87acd8992f94eca2b28f64a02cbca9ce7ca Mon Sep 17 00:00:00 2001 From: Pouzor Date: Wed, 9 Sep 2026 01:12:31 +0200 Subject: [PATCH] chore(deps): bump js-yaml to 4.3.2 for GHSA-2883-xcg3-v3hh MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The dependency-audit job fails on a high-severity advisory: js-yaml 4.0.0-4.3.1 does not limit CPU use for empty merge sources, so maxTotalMergeKeys can be bypassed. 4.3.2 is the patched release. Lockfile only — package.json already allows it at ^4.3.1, and nothing else in the tree moved. `npm audit --omit=dev --audit-level=high` now reports 0 vulnerabilities. homelable-hacs pins js-yaml at ^4.1.1 in frontend-src, inside the same vulnerable range, so it needs the same bump in its own lockfile. ha-relevant: maybe --- frontend/package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index 1f4e88e..4a125e9 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -7194,9 +7194,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", - "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", + "version": "4.3.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz", + "integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==", "funding": [ { "type": "github",