Skip to content

chore(deps): bump js-yaml from 4.3.0 to 5.2.1 in /tools/catalog-build#487

Merged
soyalejolopez merged 2 commits into
masterfrom
dependabot/npm_and_yarn/tools/catalog-build/js-yaml-5.2.1
Jul 23, 2026
Merged

chore(deps): bump js-yaml from 4.3.0 to 5.2.1 in /tools/catalog-build#487
soyalejolopez merged 2 commits into
masterfrom
dependabot/npm_and_yarn/tools/catalog-build/js-yaml-5.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.0 to 5.2.1.

Changelog

Sourced from js-yaml's changelog.

[5.2.1] - 2026-07-02

Fixed

  • Add Map support to !!omap (should work when realMapTag used)

Security

  • Remove quadratic complexity from !!omap addItem. Regression from v5 (usually not critical, because YAML11_SCHEMA is not default anymore).
Commits
  • ac16b42 5.2.1 released
  • 4a864e5 Deps bump
  • 39f3211 !!omap: add Map support and remove quadratic complexity
  • ff17f1e Changelog update
  • 8ed15f1 deps bump
  • 1a562dc Fix changelog link
  • c28ed5e 5.2.0 released
  • 125cd5a Add maxAliases option
  • 3105455 Replace maxMergeSeqLengthoption with maxTotalMergeKeys (more robust)
  • 39d00d6 numbers: Drop boxed numbers support, simplify .identify() checks, clarify rou...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 5.2.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...5.2.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: javascript. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 22, 2026
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🛰️ PR Sweeper report

Risk: 🟢 LOW · Security gate: ✅ passing · Files: 3

🔒 Automated guardrails (authoritative)

No secret, PII, file-policy, or scope issues detected. ✅

🤖 Dual-model AI review (advisory)

Deep-reasoning revieweropenai/o3 · verdict: request_changes · risk: medium

The only functional change is swapping js-yaml 4.x for a 5.2.1 release and adjusting the import. Because 5.2.1 is not an official release, this introduces a high supply-chain risk that outweighs the benefits of the change.

Security notes:

  • high tools/catalog-build/package.json:14 — The PR replaces the well-known latest js-yaml 4.1.0 with a 5.2.1 release that does not (yet) exist in the official js-yaml project. Pulling an unpublished or typosquatted major version is a classic supply-chain attack vector.
  • high tools/catalog-build/package-lock.json:101 — Lockfile now pins to js-yaml 5.2.1 from an unknown tarball. Provenance of this tarball is unclear; integrity hash differs from the legitimate 4.x line.

Quality notes:

  • tools/catalog-build/index.js — Changing import yaml from 'js-yaml' to import * as yaml is fine for ESM, but will break if the module starts exporting ESM named exports only. This should be tested once a safe version is chosen.

✅ Suggested next steps

  • Revert to the latest vetted js-yaml 4.1.0 unless there is a signed statement from the upstream maintainers that 5.x is legitimate.
  • If upgrading, validate the package on npm, check its publisher, changelog, and security advisories.
  • After selecting a safe version, run npm install --package-lock-only to regenerate a clean lockfile and commit that instead of hand-editing the lockfile.

The automated guardrails are authoritative and gate the security status. The AI review is advisory and never auto-merges. Thanks for contributing to FastTrack! 🛩️

@github-actions github-actions Bot added sweeper:ai-reviewed PR Sweeper: dual-model AI review attached sweeper:risk-low PR Sweeper: low risk labels Jul 22, 2026
js-yaml v5 is ESM-only and no longer ships a default export, so `import yaml from 'js-yaml'` throws at load time and breaks `npm run check`. Switch to a namespace import; yaml.load and yaml.JSON_SCHEMA remain available as named exports.
@soyalejolopez
soyalejolopez merged commit 0991552 into master Jul 23, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/tools/catalog-build/js-yaml-5.2.1 branch July 23, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file sweeper:ai-reviewed PR Sweeper: dual-model AI review attached sweeper:risk-low PR Sweeper: low risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant