Skip to content

chore(deps): bump js-yaml from 4.3.0 to 5.2.1 in /tools/catalog-build#487

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/tools/catalog-build/js-yaml-5.2.1
Open

chore(deps): bump js-yaml from 4.3.0 to 5.2.1 in /tools/catalog-build#487
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/tools/catalog-build/js-yaml-5.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.0 to 5.2.1.

Changelog

Sourced from js-yaml's changelog.

[5.2.1] - 2026-07-02

Fixed

  • Add Map support to !!omap (should work when realMapTag used)

Security

  • Remove quadratic complexity from !!omap addItem. Regression from v5 (usually not critical, because YAML11_SCHEMA is not default anymore).
Commits
  • ac16b42 5.2.1 released
  • 4a864e5 Deps bump
  • 39f3211 !!omap: add Map support and remove quadratic complexity
  • ff17f1e Changelog update
  • 8ed15f1 deps bump
  • 1a562dc Fix changelog link
  • c28ed5e 5.2.0 released
  • 125cd5a Add maxAliases option
  • 3105455 Replace maxMergeSeqLengthoption with maxTotalMergeKeys (more robust)
  • 39d00d6 numbers: Drop boxed numbers support, simplify .identify() checks, clarify rou...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 5.2.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...5.2.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: javascript. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🛰️ PR Sweeper report

Risk: 🟢 LOW · Security gate: ✅ passing · Files: 2

🔒 Automated guardrails (authoritative)

No secret, PII, file-policy, or scope issues detected. ✅

🤖 Dual-model AI review (advisory)

Deep-reasoning revieweropenai/o3 · verdict: request_changes · risk: high

The PR replaces the well-known js-yaml 4.x dependency with a suspicious 5.2.1 version that is not an official release. This is a potential supply-chain attack vector and must be blocked.

Security notes:

  • high tools/catalog-build/package.json:14 — Dependency "js-yaml" is changed from ^4.1.0 (latest official release) to ^5.2.1. There is no legitimate 5.x series published by the official js-yaml maintainers; any 5.x versions that appear in npm are likely un-vetted or malicious typo-squat releases. Introducing this version creates a serious supply-chain attack surface.
  • high tools/catalog-build/package-lock.json:101 — Lockfile now pins js-yaml@​5.2.1 resolved from https://registry.npmjs.org/js-yaml/-/js-yaml-5.2.1.tgz with a new binary entry (bin/js-yaml.mjs). This indicates the project will actually download and execute untrusted code that is almost certainly NOT the official js-yaml package.

Quality notes:

  • tools/catalog-build/package.json — Downgrading/altering major version without any explanation in the PR description violates contribution guidelines requiring rationale in README or commit message.

✅ Suggested next steps

  • Revert the change and keep using the official latest js-yaml@​^4.1.0 (or verify a legitimate upcoming 4.x release).
  • If an upgrade is truly required, provide evidence that 5.2.1 is an authentic release from the js-yaml maintainers (e.g., changelog, repository tags, PGP signatures).
  • Run npm audit / snyk test and manual code review of the 5.2.1 tarball to confirm no malicious or obfuscated code (network calls, exec, postinstall scripts, etc.).
  • Document the motivation for any dependency version change in the PR description and update the project’s change log.

The automated guardrails are authoritative and gate the security status. The AI review is advisory and never auto-merges. Thanks for contributing to FastTrack! 🛩️

@github-actions github-actions Bot added sweeper:ai-reviewed PR Sweeper: dual-model AI review attached sweeper:risk-low PR Sweeper: low risk labels Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file sweeper:ai-reviewed PR Sweeper: dual-model AI review attached sweeper:risk-low PR Sweeper: low risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants