Skip to content

Fix js-yaml vulnerability and publish standards 0.6.3 - #21

Merged
dudetru25 merged 3 commits into
mainfrom
fix/dependabot-undici-vulnerabilities
Aug 13, 2026
Merged

Fix js-yaml vulnerability and publish standards 0.6.3#21
dudetru25 merged 3 commits into
mainfrom
fix/dependabot-undici-vulnerabilities

Conversation

@dudetru25

@dudetru25 dudetru25 commented Aug 13, 2026

Copy link
Copy Markdown
Member

Summary

  • update the locked transitive js-yaml dependency from 4.3.0 to 4.3.1
  • close Dependabot alert #73 / GHSA-5p4m-2wfm-xmqj
  • include the existing standards 0.6.3 policy commit already present on the fix branch

Security invariant

Untrusted YAML processed by development tooling must not use a js-yaml release vulnerable to quadratic CPU consumption during !!omap resolution.

Validation

  • npm ci --ignore-scripts --min-release-age=7
  • npm run validate
  • 205 tests passed across runtime, simplified-context, and remote-shell suites
  • npm audit reported 0 vulnerabilities

The locked version was published on 2026-07-31 and satisfies the repository seven-day package-age gate.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@dudetru25
dudetru25 merged commit e75d5c4 into main Aug 13, 2026
8 checks passed
@dudetru25
dudetru25 deleted the fix/dependabot-undici-vulnerabilities branch August 13, 2026 14:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant