Skip to content

fix(deps): update dependency js-yaml to v3.14.1#121

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/js-yaml-3.x-lockfile
Mar 17, 2023
Merged

fix(deps): update dependency js-yaml to v3.14.1#121
renovate[bot] merged 1 commit intomasterfrom
renovate/js-yaml-3.x-lockfile

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 17, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
js-yaml 3.13.1 -> 3.14.1 age adoption passing confidence

Release Notes

nodeca/js-yaml

v3.14.1

Compare Source

Security
  • Fix possible code execution in (already unsafe) .load() (in &anchor).

v3.14.0

Compare Source

Changed
  • Support safe/loadAll(input, options) variant of call.
  • CI: drop outdated nodejs versions.
  • Dev deps bump.
Fixed
  • Quote = in plain scalars #​519.
  • Check the node type for !<?> tag in case user manually specifies it.
  • Verify that there are no null-bytes in input.
  • Fix wrong quote position when writing condensed flow, #​526.

Configuration

📅 Schedule: Branch creation - "after 4am and before 7am on saturday" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 17, 2023
@renovate renovate bot force-pushed the renovate/js-yaml-3.x-lockfile branch 3 times, most recently from ede1371 to 039fde6 Compare March 17, 2023 21:08
@renovate renovate bot force-pushed the renovate/js-yaml-3.x-lockfile branch from 039fde6 to 659c42f Compare March 17, 2023 21:10
@renovate renovate bot merged commit 1dc9afa into master Mar 17, 2023
@renovate renovate bot deleted the renovate/js-yaml-3.x-lockfile branch March 17, 2023 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants