Skip to content

fix: update Antigravity js-yaml override - #3843

Open
Jeff Stock (jstock03) wants to merge 3 commits into
microsoft:mainfrom
jstock03:fix/antigravity-js-yaml-advisories
Open

fix: update Antigravity js-yaml override#3843
Jeff Stock (jstock03) wants to merge 3 commits into
microsoft:mainfrom
jstock03:fix/antigravity-js-yaml-advisories

Conversation

@jstock03

Copy link
Copy Markdown
Contributor

Why

S360 and Component Governance flag the Antigravity CLI's overridden js-yaml 4.2.0 for two related advisories. Both alerts apply to the same installed package instance, so one override and lockfile update is the smallest complete remediation.

Vulnerabilities

Change

Update only the Antigravity package's transitive js-yaml override and lockfile from 4.2.0 to 4.3.1.

Validation

  • npm ci reports zero vulnerabilities
  • npm ls js-yaml resolves js-yaml 4.3.1 overridden
  • npm run check
  • npm test passes 22 tests

Signed-off-by: Jeff Stock <jstock@microsoft.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the size/S Small PR (< 50 lines) label Aug 27, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Signed-off-by: Jeff Stock <jstock@microsoft.com>
@github-actions github-actions Bot added documentation Improvements or additions to documentation size/M Medium PR (< 200 lines) and removed size/S Small PR (< 50 lines) labels Aug 27, 2026
Signed-off-by: Jeff Stock <jstock@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant