Skip to content

build(deps-dev): Bump js-yaml from 4.3.1 to 4.3.2 in /eslint-factory in the npm_and_yarn group across 1 directory - #59629

Merged
pelikhan merged 3 commits into
mainfrom
dependabot/npm_and_yarn/eslint-factory/npm_and_yarn-56e86fd9c9
Sep 9, 2026
Merged

build(deps-dev): Bump js-yaml from 4.3.1 to 4.3.2 in /eslint-factory in the npm_and_yarn group across 1 directory#59629
pelikhan merged 3 commits into
mainfrom
dependabot/npm_and_yarn/eslint-factory/npm_and_yarn-56e86fd9c9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /eslint-factory directory: js-yaml.

Updates js-yaml from 4.3.1 to 4.3.2

Changelog

Sourced from js-yaml's changelog.

4.3.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 55.9 AIC · ⌖ 8.64 AIC · ⊞ 9K ·
Comment /souschef to run again


Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 34.8 AIC · ⌖ 8.66 AIC · ⊞ 9.2K ·
Comment /souschef to run again


Automated branch refresh attempt from PR Sous Chef. Run: https://github.com/github/gh-aw/actions/runs/34341665126

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 9.05 AIC · ⌖ 8.84 AIC · ⊞ 9.3K ·
Comment /souschef to run again

Bumps the npm_and_yarn group with 1 update in the /eslint-factory directory: [js-yaml](https://github.com/nodeca/js-yaml).


Updates `js-yaml` from 4.3.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@github-actions

This comment has been minimized.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Great work! 🚀 This dependency update looks solid. The js-yaml patch includes important security hardening for merge sequence limits (CVE mitigation) and is a straightforward, low-risk update to the package-lock.json. Everything checks out — this is ready for review!

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by ✅ Contribution Check · copilot · auto · 46.2 AIC · ⌖ 5.78 AIC · ⊞ 9.3K ·

@gh-aw-bot

Copy link
Copy Markdown
Collaborator
pr-sous-chef

@copilot Please take the next forward-progress pass on PR #59629.

  • Re-check the current HEAD and confirm the dependency bump is merge-ready.
  • Refresh the branch with the latest base changes if GitHub allows it.
  • Run the pr-finisher skill and push the smallest necessary follow-up, or summarize any maintainer-facing blocker if no code change is needed.

Generated by PR Sous Chef: https://github.com/github/gh-aw/actions/runs/34331794656

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 34.8 AIC · ⌖ 8.66 AIC · ⊞ 9.2K ·
Comment /souschef to run again

Copilot AI commented Sep 9, 2026

Copy link
Copy Markdown
Contributor
pr-sous-chef
```...

Checked HEAD 8bd0be0 and no follow-up code change was needed. Base main was fetched and the branch already contains it. Reviews: no review threads. Local validation passed (npm ci, npm run build, npm test in eslint-factory; make test-impacted-js BASE_REF=origin/main; make test-unit BASE_REF=origin/main; BASE_REF=origin/main make agent-report-progress). CI has no failed checks in the current rollup; only this agent run was still in progress during inspection, so final CI still needs normal maintainer re-trigger/refresh before merge.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please review this PR for forward progress. If there are unresolved review comments or failing checks, address them and then run the pr-finisher skill. If the branch is stale, refresh it from the base branch.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 9.05 AIC · ⌖ 8.84 AIC · ⊞ 9.3K ·
Comment /souschef to run again

…rn/eslint-factory/npm_and_yarn-56e86fd9c9

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

@copilot Please review this PR for forward progress. If there are unresolved review comments or failing checks, address them and then run the pr-finisher skill. If the branch is stale, refresh it from...

Refreshed the branch from latest main in merge commit c2dd35e342. The PR diff remains only the eslint-factory/package-lock.json js-yaml bump. No review threads or failed prior CI jobs were found. Local validation passed with BASE_REF=origin/main make agent-report-progress; secret scan and advisory check for js-yaml@4.3.2 were clean. Current CI on this agent-pushed head still needs the normal maintainer-triggered refresh before merge.

@pelikhan
pelikhan merged commit 7b6fa9c into main Sep 9, 2026
@pelikhan
pelikhan deleted the dependabot/npm_and_yarn/eslint-factory/npm_and_yarn-56e86fd9c9 branch September 9, 2026 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants