chore(deps): bump transitive js-yaml to 4.3.2 - #106
Conversation
Dependabot alert #14 (high): maxTotalMergeKeys does not limit CPU use for empty merge sources, affecting >=4.0.0 <4.3.2. Dev-only, transitive. Only the js-yaml entry changes; the lockfile was not regenerated, so the libc fields a newer npm writes stay as they are.
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Resolves Dependabot alert #14 (high): js-yaml
maxTotalMergeKeysdoes not limit CPU use for empty merge sources, affecting>=4.0.0 <4.3.2. The package is a transitive dev dependency.Only the js-yaml entry in
package-lock.jsonchanges (version, resolved, integrity). Regenerating the lockfile with a local npm 10 would also have stripped thelibcfields written by a newer npm, so that churn is left out on purpose.