-
Notifications
You must be signed in to change notification settings - Fork 2
fix(deps): update js-yaml to 3.14.2 (CVE fix) #424
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
✅ Coverage Check PassedOverall Coverage
Coverage comparison generated by |
Smoke Test Results ✅Last 2 Merged PRs:
Test Results:
Status: PASS @Copilot @Mossaka
|
Smoke Test ResultsLast 2 Merged PRs:
✅ GitHub MCP Status: PASS
|
Updates js-yaml from 3.14.1 to 3.14.2 to fix GHSA-mh29-5h37-fv8m (MODERATE, CVSS 5.3) - prototype pollution in merge (
<<operator).Dependency path:
Transitive dev dependency used by Jest for code coverage. Changes limited to
package-lock.json(version, resolved URL, integrity hash).Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.