js-yaml <= 4.1.1 has a quadratic-complexity DoS in merge-key handling via repeated aliases (GHSA-h67p-54hq-rp68 / CVE-2026-53550, medium). Patched in 4.2.0. js-yaml is dev-only here (direct devDependency + deduped transitive via eslint/@eslint/eslintrc), so shipped users are not exposed; the bump clears Dependabot alert #9 and patches the floor. The existing ^4.1.1 range already permitted 4.2.0 — this only refreshes the stale lockfile pin. npm audit: 0 vulnerabilities. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
5.4 KiB
5.4 KiB