Skip to content

Conversation

@mend-for-github-com
Copy link

This PR contains the following updates:

Package Type Update Change
js-yaml dependencies minor 3.13.0 -> 3.14.1

This PR resolves the vulnerabilities described in Issue #13


Version 3.13.0
Risk Change Critical High Medium Low
N/A 0 1 0 0
Version 3.14.1
Risk Change Critical High Medium Low
-100% 0 (--) 0 (-1 ) 0 (--) 0 (--)

Mend ensures you have the greatest risk reduction ("Recommended Fix"-highlighted in green) by removing as many vulnerabilities as possible. Click to see how we calculate risk reduction.


Release Notes

nodeca/js-yaml (js-yaml)

v3.14.1

Compare Source

Security
  • Fix possible code execution in (already unsafe) .load() (in &anchor).

v3.14.0

Compare Source

Changed
  • Support safe/loadAll(input, options) variant of call.
  • CI: drop outdated nodejs versions.
  • Dev deps bump.
Fixed
  • Quote = in plain scalars #​519.
  • Check the node type for !<?> tag in case user manually specifies it.
  • Verify that there are no null-bytes in input.
  • Fix wrong quote position when writing condensed flow, #​526.

v3.13.1

Compare Source

Security
  • Fix possible code execution in (already unsafe) .load(), #​480.

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Dec 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant