chore(deps): bump js-yaml to 4.2.0 — clear GHSA-h67p-54hq-rp68 (#1338)

js-yaml <= 4.1.1 has a quadratic-complexity DoS in merge-key handling via
repeated aliases (GHSA-h67p-54hq-rp68 / CVE-2026-53550, medium). Patched in
4.2.0. js-yaml is dev-only here (direct devDependency + deduped transitive via
eslint/@eslint/eslintrc), so shipped users are not exposed; the bump clears
Dependabot alert #9 and patches the floor. The existing ^4.1.1 range already
permitted 4.2.0 — this only refreshes the stale lockfile pin. npm audit: 0
vulnerabilities.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-06-16 09:28:52 -04:00
committed by GitHub
parent f5a3c5f586
commit 03428324aa
2 changed files with 15 additions and 5 deletions

18
package-lock.json generated
View File

@@ -27,7 +27,7 @@
"eslint-plugin-no-only-tests": "^3.4.0",
"fast-check": "^4.8.0",
"globals": "^16.5.0",
"js-yaml": "^4.1.1",
"js-yaml": "^4.2.0",
"typescript": "^6.0.3",
"typescript-eslint": "^8.60.0"
},
@@ -3828,10 +3828,20 @@
"license": "MIT"
},
"node_modules/js-yaml": {
"version": "4.1.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz",
"integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==",
"version": "4.2.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
"dev": true,
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/puzrin"
},
{
"type": "github",
"url": "https://github.com/sponsors/nodeca"
}
],
"license": "MIT",
"dependencies": {
"argparse": "^2.0.1"

View File

@@ -62,7 +62,7 @@
"eslint-plugin-no-only-tests": "^3.4.0",
"fast-check": "^4.8.0",
"globals": "^16.5.0",
"js-yaml": "^4.1.1",
"js-yaml": "^4.2.0",
"typescript": "^6.0.3",
"typescript-eslint": "^8.60.0"
},