chore(security): bump js-yaml to 4.3.2 in datasheetsChat (closes #81) - #13
Merged
cdbartholomew merged 1 commit intoSep 25, 2026
Conversation
Closes Dependabot alert #81 (GHSA-2883-xcg3-v3hh, high). js-yaml 4.3.1 -> 4.3.2 via the existing root overrides entry.
cdbartholomew
deleted the
chore/security-daily-20260914-rag-101-workshop-npm-datasheetschat
branch
September 25, 2026 20:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Recreates the Dependabot fix for the remaining fixable alert on
datasheetsChat/package-lock.jsonon a human-authored branch so it gets CI.Closes
js-yamlWhat changed
The root
overridesentry"js-yaml": "^4.3.1"was already floor-pinning this package, so the fix is a one-character floor bump to"^4.3.2"plus a re-lock. The caret keeps resolution on the 4.x line (4.3.2 is the current 4.x tip; 5.x is a major bump and remains a maintainer decision). The sole consumer,@eslint/eslintrc, declaresjs-yaml: ^4.1.1, so 4.3.2 is in-range for the parent — the override is not forcing anything the tree would reject.Diff is 4 lines across 2 files: the override line plus the single
js-yamllockfile entry. No native-package churn.Regenerated with
npm install --package-lock-only --ignore-scripts. No--force, no--legacy-peer-deps.Verification (differential, against a pristine
maincontrol worktree)This repo's only CI workflow is
secret-scan.yml, andmainis already red onnpm run build, so both gates were run on the branch and on an untouchedmaincheckout at the same commit and the outputs compared.main(control)npm cinpm run buildsrc/app/api/chat/route.ts:134LanguageModelV1not assignable toLanguageModelnpm run lintnext lintfinds no ESLint config and drops into an interactive promptnpm run testtestscript inpackage.jsonBuild logs from the two trees are byte-identical after normalising the compile-timing string.
Because
js-yamlis a dev-scope dependency that the build does not exercise, the upgraded package was also smoke-tested directly:loadof a nested mapping/sequence, adump→loadround-trip that compares JSON-identical, and confirmation that the!!js/functiontag is still rejected.Interaction with the other open PRs on this lockfile
PRs #11 (
postcss-selector-parser) and #12 (@humanfs/node) are open against the samedatasheetsChat/package-lock.json. Merge-compatibility was tested rather than assumed — this branch was test-merged against both heads, individually and together:In every order the merged lockfile keeps all three fixes (
js-yaml4.3.2,postcss-selector-parser6.1.4,@humanfs/node0.16.8). No rebase or re-lock is required for any merge order — the three edits land in disjoint regions of the lockfile.That said, this is now the third open PR against this one lockfile, and none of the three have been merged. Flagging the pile-up.
Not included
Alert #80 (
@ai-sdk/provider-utils, GHSA-866g-f22w-33x8, low) is deliberately not bundled here, and its status has changed in a way worth reading — see the note appended to #10.