Skip to content

chore: Bump js-yaml from 4.3.0 to 4.3.1 - #707

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-4.3.1
Open

chore: Bump js-yaml from 4.3.0 to 4.3.1#707
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-4.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 12, 2026
@dependabot
dependabot Bot requested a review from a team August 12, 2026 06:38
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 31570767794

Coverage remained the same at 84.943%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 6056
Covered Lines: 5395
Line Coverage: 89.09%
Relevant Branches: 2153
Covered Branches: 1578
Branch Coverage: 73.29%
Branches in Coverage %: Yes
Coverage Strength: 642.83 hits per line

💛 - Coveralls

@socket-security

socket-security Bot commented Aug 12, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​js-yaml@​4.3.0 ⏵ 4.3.1100 +1100 +16100 +194100

View full report

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.3.1 branch from 206a945 to 0a54b8c Compare August 27, 2026 12:20
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.3.1 branch from 0a54b8c to 44ac4ec Compare August 27, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant