Skip to content

Conversation

@GarboMuffin
Copy link
Member

not clear why dependabot didn't want to update this

anyways, it fixes a "moderate" severity security bug that actually is not really a security bug in our context since this is only used by the eslintrc parser. if someone can get malicious yaml into the eslintrc parser, they can also just get malicious js into the eslintrc js file and make this vulnerability redundant

@github-actions github-actions bot added the pr: other Pull requests that neither add new extensions or change existing ones label Nov 22, 2025
@GarboMuffin GarboMuffin added dependencies Pull requests that update a dependency file and removed pr: other Pull requests that neither add new extensions or change existing ones labels Nov 22, 2025
@GarboMuffin GarboMuffin merged commit d6952a1 into master Nov 22, 2025
4 checks passed
@GarboMuffin GarboMuffin deleted the upd-jsyaml branch November 22, 2025 20:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants