Commit 3b28852
chore(deps): bump js-yaml to fix prototype pollution in merge (#5709)
Fixes prototype pollution via merge (<<) in two series:
- 3.x: bumps 3.14.1 -> 3.14.2 via parent-scoped resolutions for the
four 3.x consumers (@istanbuljs/load-nyc-config, @yarnpkg/parsers,
cosmiconfig, front-matter), preserving 3.x API compatibility
- 4.x: bumps 4.1.0 -> 4.1.1 via unscoped resolution
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: LucasZF <lucas-zimerman1@hotmail.com>1 parent a02d765 commit 3b28852
2 files changed
Lines changed: 11 additions & 17 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
63 | 68 | | |
64 | 69 | | |
65 | 70 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23433 | 23433 | | |
23434 | 23434 | | |
23435 | 23435 | | |
23436 | | - | |
23437 | | - | |
23438 | | - | |
| 23436 | + | |
| 23437 | + | |
| 23438 | + | |
23439 | 23439 | | |
23440 | | - | |
23441 | | - | |
23442 | | - | |
23443 | | - | |
23444 | | - | |
23445 | | - | |
23446 | | - | |
23447 | | - | |
23448 | | - | |
23449 | | - | |
23450 | | - | |
23451 | | - | |
23452 | | - | |
| 23440 | + | |
| 23441 | + | |
23453 | 23442 | | |
23454 | 23443 | | |
23455 | | - | |
| 23444 | + | |
23456 | 23445 | | |
23457 | 23446 | | |
23458 | 23447 | | |
| |||
0 commit comments