Skip to content

chore(deps): override vulnerable js-yaml versions - #924

Merged
frahlg merged 1 commit into
masterfrom
agent/fix-changesets-js-yaml-audit
Aug 16, 2026
Merged

chore(deps): override vulnerable js-yaml versions#924
frahlg merged 1 commit into
masterfrom
agent/fix-changesets-js-yaml-audit

Conversation

@frahlg

@frahlg frahlg commented Aug 16, 2026

Copy link
Copy Markdown
Member

Pin both js-yaml lines used by Changesets to their fixed releases: 3.15.1 and 4.3.1. This is dev-only release tooling; FTW runtime has no npm production vulnerability. Before: npm audit reported 14 transitive findings, including one high. After: npm audit reports 0. Changesets status works, 339 web tests pass, and full make verify passes. This should carry the no-changeset label because it does not ship runtime behavior; #824 will regenerate its lockfile version hunk after merge.

@frahlg frahlg added the no-changeset PR intentionally exempt from the changeset requirement (dev tooling / non-shipping) label Aug 16, 2026
@frahlg
frahlg marked this pull request as ready for review August 16, 2026 12:28
@frahlg
frahlg requested a review from miravoss26 August 16, 2026 12:29
@frahlg

frahlg commented Aug 16, 2026

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 97a4025498

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@frahlg
frahlg merged commit f0c9ad2 into master Aug 16, 2026
14 of 15 checks passed
@frahlg
frahlg deleted the agent/fix-changesets-js-yaml-audit branch August 16, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changeset PR intentionally exempt from the changeset requirement (dev tooling / non-shipping)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant