* chore(deps-dev): bump js-yaml Bumps the npm_and_yarn group with 1 update in the / directory: [js-yaml](https://github.com/nodeca/js-yaml). Updates `js-yaml` from 4.3.1 to 4.3.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.2 dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> * chore: refresh vendored js-yaml to 4.3.2 (#4565) lint-vendored-deps caught the drift: this PR's lockfile-only bump left gsd-core/bin/lib/vendor/js-yaml.cjs and the package.json pin behind the new js-yaml 4.3.2 resolved by package-lock.json (merge-key CPU-limit backport, GHSA for excessive merge-key processing). Refreshes the vendored copy from node_modules and bumps the manifest pin to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs: add Security changeset for js-yaml 4.3.2 vendor bump (#4565) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Tom Boucher <trekkie@nomorestars.com> Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>