Skip to content

fix(deps):-update-dependency-yaml-to-v2.2.2-[security]#214

Open
sunnydanu wants to merge 1 commit into
developing/2.0.0from
fix(deps)--update-dependency-yaml-to-v2-2-2--security-
Open

fix(deps):-update-dependency-yaml-to-v2.2.2-[security]#214
sunnydanu wants to merge 1 commit into
developing/2.0.0from
fix(deps)--update-dependency-yaml-to-v2-2-2--security-

Conversation

@sunnydanu

@sunnydanu sunnydanu commented Oct 27, 2024

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
yaml (source) 2.2.1 -> 2.2.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-2251

Uncaught Exception in GitHub repository eemeli/yaml starting at version 2.0.0-5 and prior to 2.2.2.


Release Notes

eemeli/yaml (yaml)

v2.2.2

Compare Source

This patch release includes a fix for an error that could be thrown in parseDocument for degenerate input. Otherwise, it's a patch release uplifting a few fixes from the ongoing v2.3 work to v2.2:

  • Corner case failure in error pretty-printer (CVE-2023-2251)
  • Use correct argument order when stringifying flow collection comments (#​443)
  • First-line folding for block scalars (#​422)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.



**Note**: This PR incorporates contributions from upstream [PR-#898](https://github.com/CorentinTh/it-tools/pull/898) of [CorentinTh/it-tools](https://github.com/CorentinTh/it-tools). All original commits and authorship are retained. Some adjustments may have been made for compatibility or bug fixes.

@vercel

vercel Bot commented Oct 27, 2024

Copy link
Copy Markdown

Deployment failed with the following error:

Too many requests - try again in 1 minute (more than 60, code: "api-deployments-flood").

@sunnydanu sunnydanu added the P2 Priority 2 : tech debt label Nov 2, 2024
@sunnydanu sunnydanu enabled auto-merge November 2, 2024 10:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Priority 2 : tech debt

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant