Skip to content

chore(deps-dev): bump js-yaml from 4.3.1 to 4.3.2 in /web-vue - #183

Merged
youngfish42 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/web-vue/js-yaml-4.3.2
Sep 14, 2026
Merged

youngfish42 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/web-vue/js-yaml-4.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.1 to 4.3.2.

Changelog

Sourced from js-yaml's changelog.

4.3.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 14, 2026
@monkeyscan

monkeyscan Bot commented Sep 14, 2026

Copy link
Copy Markdown

PR Title: chore(deps-dev): bump js-yaml from 4.3.1 to 4.3.2 ...

Commit: 06ca1c8

本次变更仅涉及 1 个文件:web-vue/package-lock.json 的 3 行改动,位于 node_modules/js-yaml 条目,将 js-yaml 由 4.3.1 升级到 4.3.2,并同步更新 resolved 的 tarball URL 与 sha512 integrity 哈希;dev 标记、license、bin、dependencies(argparse ^2.0.1)等元数据均未变化。

一致性核验:

  • 该包为传递性 dev 依赖,仅被 eslint 与 @eslint/eslintrc 以 "^4.1.0" 引用(第 561、2875 行),4.3.2 仍满足该语义化版本范围,不会造成解析冲突。
  • 全文搜索 "js-yaml" 仅命中 5 处(2 处依赖声明、1 处包定义、1 处 resolved、1 处 bin 路径),不存在需要同步更新的嵌套条目或重复定义。
  • web-vue/package.json 未改动(无新增/变更直接依赖),属于标准的锁文件刷新(如 npm update / 依赖机器人补丁升级)。

评估结论:改动为锁文件中单个 dev 传递依赖的补丁级版本刷新,版本、tarball 地址与完整性哈希三者自洽,未引入版本漂移、范围不满足或锁定不一致问题。未发现可被证据支撑的正确性、安全性、数据完整性或兼容性风险,故不提交 finding。

@youngfish42
youngfish42 merged commit f66aff4 into main Sep 14, 2026
3 checks passed
@youngfish42
youngfish42 deleted the dependabot/npm_and_yarn/web-vue/js-yaml-4.3.2 branch September 14, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant