Compare commits

..
Author SHA1 Message Date
renovate[bot] 52c89acab1 fix(ui): update dependency js-yaml to v4.3.2 [security] 2026-10-03 23:10:12 +00:00
2 changed files with 5 additions and 5 deletions
+1 -1
View File
@@ -91,7 +91,7 @@
"driver.js": "1.4.0",
"framer-motion": "11.18.2",
"import-in-the-middle": "3.3.1",
"js-yaml": "4.3.1",
"js-yaml": "4.3.2",
"jwt-decode": "4.0.0",
"langchain": "1.4.0",
"lucide-react": "0.543.0",
+4 -4
View File
@@ -1,6 +1,3 @@
# pnpm 11+ workspace config. .npmrc is auth/registry only; everything else lives here.
# Reference: https://pnpm.io/supply-chain-security
packages: []
# Refuse to install on Node/pnpm outside the `engines` block in package.json.
@@ -111,7 +108,7 @@ overrides:
"@humanfs/node": "0.16.8"
# js-yaml: quadratic CPU in `!!omap` resolution (CVE-2026-59870 not backported
# to 4.3.0). Direct dep is already 4.3.1; the override lifts eslint's copy too.
"js-yaml": "4.3.1"
"js-yaml": "4.3.2"
# --- Level 1: Minimum Release Age ---
# Packages must be published for at least 1 day before they can be installed.
@@ -157,3 +154,6 @@ trustPolicyExclude:
# Block transitive dependencies from using exotic specifiers (git URLs, tarballs).
blockExoticSubdeps: true
minimumReleaseAgeExclude:
# Renovate security update: js-yaml@4.3.2
- js-yaml@4.3.2