Skip to content

chore(deps): bump js-yaml from 4.3.0 to 4.3.1 in /workspaces/bulk-import - #4252

Merged
kim-tsao merged 2 commits into
mainfrom
dependabot/npm_and_yarn/workspaces/bulk-import/js-yaml-4.3.1
Aug 11, 2026
Merged

chore(deps): bump js-yaml from 4.3.0 to 4.3.1 in /workspaces/bulk-import#4252
kim-tsao merged 2 commits into
mainfrom
dependabot/npm_and_yarn/workspaces/bulk-import/js-yaml-4.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 11, 2026
@dependabot
dependabot Bot requested a review from rm3l as a code owner August 11, 2026 14:08
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 11, 2026
@dependabot
dependabot Bot requested review from a team, debsmita1 and its-mitesh-kumar as code owners August 11, 2026 14:08
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Aug 11, 2026
@dependabot
dependabot Bot requested review from a team as code owners August 11, 2026 14:08
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@rhdh-bot
rhdh-bot force-pushed the dependabot/npm_and_yarn/workspaces/bulk-import/js-yaml-4.3.1 branch from 9a13747 to c11879a Compare August 11, 2026 14:08
@rhdh-gh-app

rhdh-gh-app Bot commented Aug 11, 2026

Copy link
Copy Markdown

Changed Packages

Package Name Package Path Changeset Bump Current Version
app-legacy workspaces/bulk-import/packages/app-legacy none v0.0.3
app workspaces/bulk-import/packages/app none v0.0.1
backend workspaces/bulk-import/packages/backend none v0.0.0
@red-hat-developer-hub/backstage-plugin-bulk-import-backend workspaces/bulk-import/plugins/bulk-import-backend patch v8.0.2
@red-hat-developer-hub/backstage-plugin-bulk-import workspaces/bulk-import/plugins/bulk-import patch v8.0.2

@codecov

codecov Bot commented Aug 11, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.02%. Comparing base (0a5c92e) to head (4bf0591).
⚠️ Report is 5 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4252   +/-   ##
=======================================
  Coverage   59.02%   59.02%           
=======================================
  Files        2451     2451           
  Lines       97934    97934           
  Branches    27305    27305           
=======================================
  Hits        57810    57810           
  Misses      39855    39855           
  Partials      269      269           
Flag Coverage Δ *Carryforward flag
adoption-insights 84.55% <ø> (ø) Carriedforward from c11879a
ai-integrations 69.76% <ø> (ø) Carriedforward from c11879a
app-defaults 69.79% <ø> (ø) Carriedforward from c11879a
augment 46.67% <ø> (ø) Carriedforward from c11879a
boost 77.63% <ø> (ø) Carriedforward from c11879a
bulk-import 72.79% <ø> (ø)
cost-management 13.55% <ø> (ø) Carriedforward from c11879a
dcm 67.21% <ø> (ø) Carriedforward from c11879a
e2e-intelligent-assistant 46.74% <ø> (ø) Carriedforward from c11879a
extensions 56.59% <ø> (ø) Carriedforward from c11879a
global-floating-action-button 71.18% <ø> (ø) Carriedforward from c11879a
global-header 66.50% <ø> (ø) Carriedforward from c11879a
homepage 47.50% <ø> (ø) Carriedforward from c11879a
install-dynamic-plugins 59.95% <ø> (ø) Carriedforward from c11879a
intelligent-assistant 75.42% <ø> (ø) Carriedforward from c11879a
konflux 91.98% <ø> (ø) Carriedforward from c11879a
lightspeed 69.02% <ø> (ø) Carriedforward from c11879a
mcp-integrations 83.40% <ø> (ø) Carriedforward from c11879a
orchestrator 71.31% <ø> (ø) Carriedforward from c11879a
quickstart 63.74% <ø> (ø) Carriedforward from c11879a
sandbox 79.56% <ø> (ø) Carriedforward from c11879a
scorecard 86.23% <ø> (ø) Carriedforward from c11879a
theme 88.77% <ø> (ø) Carriedforward from c11879a
translations 5.12% <ø> (ø) Carriedforward from c11879a
x2a 79.20% <ø> (ø) Carriedforward from c11879a

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 0a5c92e...4bf0591. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@kim-tsao

Copy link
Copy Markdown
Member

/fs-fix run yarn dedupe and commit the changes

@fullsend-ai-coder

fullsend-ai-coder Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

🤖 Finished Fix · ✅ Success · Started 6:23 PM UTC · Completed 6:36 PM UTC

Commit: c11879a · View workflow run →

Consolidate js-yaml resolution so all specifiers (^4.1.0, ^4.1.1,
^4.2.0, ^4.3.1) resolve to 4.3.1, removing the duplicate 4.3.0 entry.

Addresses review feedback on #4252
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor

🔧 Fix agent — iteration 1 (human-triggered)

Ran yarn dedupe in the bulk-import workspace per human instruction. Consolidated js-yaml resolution from two entries (4.3.0 and 4.3.1) down to a single 4.3.1 entry.

Fixed (1):

  1. run yarn dedupe (workspaces/bulk-import/yarn.lock): Ran yarn dedupe in the bulk-import workspace, consolidating js-yaml so all specifiers (^4.1.0, ^4.1.1, ^4.2.0, ^4.3.1) resolve to 4.3.1, removing the duplicate 4.3.0 entry

Tests: passed

Updated by fullsend fix agent

@sonarqubecloud

Copy link
Copy Markdown

@kim-tsao
kim-tsao merged commit 9ff7395 into main Aug 11, 2026
27 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/workspaces/bulk-import/js-yaml-4.3.1 branch August 11, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code workspace/bulk-import

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant