Skip to content

fix(deps): pin js-yaml to 4.3.1 - #181

Closed
petercr wants to merge 1 commit into
TheOrcDev:mainfrom
petercr:agent/js-yaml-security
Closed

fix(deps): pin js-yaml to 4.3.1#181
petercr wants to merge 1 commit into
TheOrcDev:mainfrom
petercr:agent/js-yaml-security

Conversation

@petercr

@petercr petercr commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

What changed

  • Pin the direct js-yaml dependency to 4.3.1.
  • Update the workspace override and pnpm lockfile so transitive Electron tooling resolves the same patched version.

Why

The repository currently resolves js-yaml 4.3.0. This update keeps the direct and transitive dependency graph on the patched 4.3.1 release.

Validation

  • git diff --check
  • Lockfile, workspace override, and package manifest updated together.
  • Dependency install and advisory checks are left to GitHub Actions.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: b85da45f-5f9b-4026-b78e-1a3641dd891c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@petercr

petercr commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by PR #180, which now contains both the Windows recording/FFmpeg fix and the js-yaml security update.

@petercr petercr closed this Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant