Skip to content

[Snyk] Upgrade js-yaml from 5.2.2 to 5.2.3 - #444

Open
l0rd wants to merge 1 commit into
mainfrom
snyk-upgrade-8f531f2c011c2d90eb7939276af7ea43
Open

[Snyk] Upgrade js-yaml from 5.2.2 to 5.2.3#444
l0rd wants to merge 1 commit into
mainfrom
snyk-upgrade-8f531f2c011c2d90eb7939276af7ea43

Conversation

@l0rd

@l0rd l0rd commented Aug 22, 2026

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to upgrade js-yaml from 5.2.2 to 5.2.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released 21 days ago.

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade js-yaml from 5.2.2 to 5.2.3.

See this package in yarn:
js-yaml

See this project in Snyk:
https://app.snyk.io/org/devfile/project/7e16b032-bfac-469a-9236-69cd422663e7?utm_source=github&utm_medium=referral&page=upgrade-pr
@l0rd

l0rd commented Aug 22, 2026

Copy link
Copy Markdown
Author

Merge Risk: Low

This is a patch version upgrade that contains several bug fixes. The changes address issues such as preventing prototype fallback during tag resolution, correcting timestamp parsing, and improving the handling of certain YAML structures. No breaking changes or new features were introduced.

Fixes:

  • Prevent prototype fallback when resolving tags and mapping entries. [4]
  • Correctly resolve !!timestamp for years between 0000-0099. [4]
  • Preserve implicit null mapping values before document markers. [4]

Source: GitHub CHANGELOG.md

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@l0rd
l0rd requested review from ibuziuk, svor and tolusha as code owners August 22, 2026 07:45
@openshift-ci

openshift-ci Bot commented Aug 22, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: l0rd

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 7c4c2538-879d-4236-b39b-a8d6d7d6484d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants