Commit 2da06b4
committed
chore: upgrade js-yaml to ^4.2.0 to address CVE-2026-53550
Refresh the lockfile so all transitive js-yaml instances resolve to
4.2.0, which fixes the quadratic-complexity DoS in merge key handling.
Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1360/sourcebot-devsourcebot-cve-2026-53550-js-yaml-quadratic-complexity-dos#agent-session-b16750d8)
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>1 parent ed74594 commit 2da06b4
2 files changed
Lines changed: 4 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16247 | 16247 | | |
16248 | 16248 | | |
16249 | 16249 | | |
16250 | | - | |
16251 | | - | |
| 16250 | + | |
| 16251 | + | |
16252 | 16252 | | |
16253 | 16253 | | |
16254 | 16254 | | |
16255 | 16255 | | |
16256 | | - | |
| 16256 | + | |
16257 | 16257 | | |
16258 | 16258 | | |
16259 | 16259 | | |
| |||
0 commit comments