Skip to content

Update js-yaml to ~4.2.0 to address GHSA-h67p-54hq-rp68#5847

Draft
Copilot wants to merge 2 commits into
mainfrom
copilot/upgrade-js-yaml-dependency
Draft

Update js-yaml to ~4.2.0 to address GHSA-h67p-54hq-rp68#5847
Copilot wants to merge 2 commits into
mainfrom
copilot/upgrade-js-yaml-dependency

Conversation

Copilot AI commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

js-yaml ~4.1.0 has a known advisory (GHSA-h67p-54hq-rp68) for poor performance characteristics with certain input (ReDoS-class behavior). Bumping to ~4.2.0 resolves it.

Changes

  • libraries/rush-lib/package.json — bump js-yaml ~4.1.0~4.2.0
  • apps/api-documenter/package.json — same
  • apps/lockfile-explorer/package.json — same
  • repo-scripts/doc-plugin-rush-stack/package.json — same
  • common/config/subspaces/default/pnpm-lock.yamlrush update resolves to js-yaml@4.2.0
  • common/changes/@microsoft/rush/ — change file with bump type none

Copilot AI changed the title [WIP] Update js-yaml dependency to version 4.2.x to fix security issue Update js-yaml to ~4.2.0 to address GHSA-h67p-54hq-rp68 Jun 24, 2026
Copilot AI requested a review from dmichon-msft June 24, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Needs triage

Development

Successfully merging this pull request may close these issues.

2 participants