Skip to content

Upgrade js-yaml to 4.3.1 to resolve high vulnerability - #959

Merged
petyosi merged 2 commits into
mdx-editor:mainfrom
alexander-neuschl-tu-dresden-de:patch-1
Aug 21, 2026
Merged

petyosi merged 2 commits into
mdx-editor:mainfrom
alexander-neuschl-tu-dresden-de:patch-1

Conversation

@alexander-neuschl-tu-dresden-de

Copy link
Copy Markdown
Contributor

The vulnerable versions of js-yaml were expanded to include 4.3.0 which we recently updated to: GHSA-5p4m-2wfm-xmqj

This was fixed by a backported update which resulted in the new version 4.3.1
nodeca/js-yaml@c3cc4b0

The vulnerable versions of js-yaml were expanded to include 4.3.0 which we recently updated to: GHSA-5p4m-2wfm-xmqj

This was fixed by a backported update which resulted in the new version 4.3.1
nodeca/js-yaml@c3cc4b0
@petyosi
petyosi merged commit b5bc01b into mdx-editor:main Aug 21, 2026
4 checks passed
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 4.2.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants