Skip to content

refactor: Bump js-yaml from 3.14.2 to 3.15.2 - #10653

Merged
mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/js-yaml-3.15.2
Sep 22, 2026
Merged

mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/js-yaml-3.15.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 3.14.2 to 3.15.2.

Changelog

Sourced from js-yaml's changelog.

3.15.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.

3.15.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

3.15.0 - 2026-06-27

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one safeLoad() / safeLoadAll() call.
Commits

@dependabot dependabot Bot added dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code labels Sep 6, 2026
@codecov

codecov Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.83%. Comparing base (adac202) to head (8879565).

Additional details and impacted files
@@            Coverage Diff             @@
##            alpha   #10653      +/-   ##
==========================================
- Coverage   93.84%   93.83%   -0.01%     
==========================================
  Files         192      192              
  Lines       16875    16875              
  Branches      252      252              
==========================================
- Hits        15836    15835       -1     
- Misses       1017     1018       +1     
  Partials       22       22              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.2 branch 3 times, most recently from 03465c3 to 93a58b4 Compare September 13, 2026 12:20
@coderabbitai

coderabbitai Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f6d00989-58d9-42b0-b34c-eeca0ea89dbc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.2 branch from 93a58b4 to ae88628 Compare September 13, 2026 20:53
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.2 branch 3 times, most recently from ea90108 to 3245192 Compare September 22, 2026 17:14
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.2 to 3.15.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.2 branch from 3245192 to 8879565 Compare September 22, 2026 20:44
@mtrezza

mtrezza commented Sep 22, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with alpha! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@mtrezza
mtrezza merged commit 7cac84a into alpha Sep 22, 2026
41 of 43 checks passed
@mtrezza
mtrezza deleted the dependabot/npm_and_yarn/js-yaml-3.15.2 branch September 22, 2026 22:23
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.1-alpha.15

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Sep 22, 2026
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.1

@parseplatformorg parseplatformorg added the state:released Released as stable version label Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code state:released Released as stable version state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants