Skip to content

build(deps): bump js-yaml from 4.3.0 to 5.2.2 in the npm group across 1 directory - #83

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-33beca4d61
Open

build(deps): bump js-yaml from 4.3.0 to 5.2.2 in the npm group across 1 directory#83
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-33beca4d61

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 1 update in the / directory: js-yaml.

Updates js-yaml from 4.3.0 to 5.2.2

Changelog

Sourced from js-yaml's changelog.

[5.2.2] - 2026-07-24

Fixed

  • Quote flow scalars where a colon precedes a flow indicator, #773.

Security

  • Avoid exponential parsing time for nested flow sequence pairs.

[5.2.1] - 2026-07-02

Fixed

  • Add Map support to !!omap (should work when realMapTag used)

Security

  • Remove quadratic complexity from !!omap addItem. Regression from v5 (usually not critical, because YAML11_SCHEMA is not default anymore).
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 23, 2026
@dependabot dependabot Bot changed the title build(deps): bump js-yaml from 4.2.0 to 5.1.0 in the npm group build(deps): bump js-yaml from 4.3.0 to 5.2.1 in the npm group across 1 directory Jul 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-33beca4d61 branch 2 times, most recently from 53f2dd2 to 401f7fd Compare July 14, 2026 15:05
Bumps the npm group with 1 update in the / directory: [js-yaml](https://github.com/nodeca/js-yaml).


Updates `js-yaml` from 4.3.0 to 5.2.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...5.2.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump js-yaml from 4.3.0 to 5.2.1 in the npm group across 1 directory build(deps): bump js-yaml from 4.3.0 to 5.2.2 in the npm group across 1 directory Jul 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-33beca4d61 branch from 401f7fd to f0c724d Compare July 28, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants