Update dependency js-yaml to v4.3.2 - #22
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
June 11, 2026 14:40
0eb9788 to
449bf84
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
June 26, 2026 23:51
449bf84 to
7c696a1
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
2 times, most recently
from
July 30, 2026 17:14
96fa8e1 to
fe507e1
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
July 31, 2026 19:47
fe507e1 to
87155d2
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
August 11, 2026 20:56
87155d2 to
5d6c775
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
August 26, 2026 20:43
5d6c775 to
5999106
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
August 27, 2026 01:50
5999106 to
980d35d
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
September 3, 2026 20:24
980d35d to
d5b7cb6
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
September 15, 2026 21:46
d5b7cb6 to
aa922dd
Compare
renovate
Bot
force-pushed
the
renovate/js-yaml-4.x-lockfile
branch
from
September 24, 2026 18:59
aa922dd to
03fe864
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.1.0→4.3.2Release Notes
nodeca/js-yaml (js-yaml)
v4.3.2Compare Source
v4.3.1Compare Source
v4.3.0Compare Source
v4.2.0Compare Source
Added
docs/safety.mdwith notes about processing untrusted YAML.maxDepth(100) loader option. Not a problem, but gives a betterexception instead of RangeError on stack overflow.
maxMergeSeqLength(20) loader option. Not a problem aftermergefix,but an additional restriction for safety.
dist/builds.Changed
dist/files are no longer kept in the repository.Fixed
Security
elements (makes sense for malformed files > 10K).
v4.1.1Compare Source
Security
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.