[Deps] Fix js-yaml prototype pollution vulnerability #372
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Security Fix
This PR addresses a MODERATE severity vulnerability in the
js-yamldependency used by the dev dependency chain.Vulnerability Details
js-yaml(via@istanbuljs/load-nyc-config)<3.14.23.14.2<<) operatorImpact
This vulnerability is in a dev dependency (
@istanbuljs/load-nyc-config→babel-plugin-istanbul→@jest/transform→ts-jest) used for test coverage instrumentation. It does not affect production code.Changes
js-yamlfrom3.14.1to3.14.2inpackage-lock.jsonnpm audit fixVerification
✅ All tests pass: 572 tests passed (18 test suites)
✅ No breaking changes detected
✅ Zero vulnerabilities remain:
npm auditreports 0 vulnerabilitiesReferences
Generated by Dependency Security Monitor Workflow