Skip to content

Conversation

@v-abhishera
Copy link

@v-abhishera v-abhishera commented Jan 4, 2026

Description

Update js-yaml to 3.14.2 in kubernetes-common-package to resolve prototype pollution vulnerability

https://dev.azure.com/mseng/AzureDevOps/_workitems/edit/2345545

Summarize the changes made in this PR clearly and concisely. Highlight the purpose and impact of the changes.

Resolves a prototype pollution vulnerability in js-yaml that allowed malicious YAML documents to inject properties into Object.prototype


Package Name

[kubernetes-common]


Risk Assessment

Low


Unit Tests Added or Updated

  • Unit tests added or updated
  • Manual tests performed

Checklist


@v-abhishera
Copy link
Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants