Skip to content

Bump js-yaml and node-red#1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-133bf8486c
Open

Bump js-yaml and node-red#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-133bf8486c

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 3, 2026

Bumps js-yaml to 4.1.1 and updates ancestor dependency node-red. These dependencies need to be updated together.

Updates js-yaml from 4.1.0 to 4.1.1

Changelog

Sourced from js-yaml's changelog.

[4.1.1] - 2025-11-12

Security

  • Fix prototype pollution issue in yaml merge (<<) operator.
Commits

Updates node-red from 3.1.15 to 4.1.6

Release notes

Sourced from node-red's releases.

4.1.6

What's Changed

New Contributors

Full Changelog: node-red/node-red@4.1.5...4.1.6

4.1.5: Maintenance Release

What's Changed

Full Changelog: node-red/node-red@4.1.4...4.1.5

4.1.4

What's Changed

New Contributors

Full Changelog: node-red/node-red@4.1.3...4.1.4

4.1.3: Maintenance Release

What's Changed

... (truncated)

Changelog

Sourced from node-red's changelog.

4.1.6: Maintenance Release

4.1.5: Maintenance Release

4.1.4: Maintenance Release

4.1.3: Maintenance Release

Editor

Runtime

Nodes

... (truncated)

Commits
  • f78e6b6 Merge pull request #5503 from node-red/rel416
  • 0ea90f5 Merge branch 'master' into rel416
  • b9d997c Merge pull request #5502 from node-red/update-deps
  • b671813 Bump for 4.1.6 release
  • 35e3034 Bump dependencies
  • f049a33 Merge pull request #5500 from node-red/5487-support-palette-theme-plugin
  • 5e83d10 Merge pull request #5501 from node-red/5497-config-tooltip-text
  • 4cf4817 Merge pull request #5499 from node-red/palette-updates
  • ae81bc1 Merge branch 'master' into palette-updates
  • 97f9ed4 Ensure config sidebar tooltip handles html content
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 3, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-133bf8486c branch from 127500b to 90ae20e Compare March 5, 2026 19:40
Bumps [js-yaml](https://github.com/nodeca/js-yaml) to 4.1.1 and updates ancestor dependency [node-red](https://github.com/node-red/node-red). These dependencies need to be updated together.


Updates `js-yaml` from 4.1.0 to 4.1.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.1.0...4.1.1)

Updates `node-red` from 3.1.15 to 4.1.6
- [Release notes](https://github.com/node-red/node-red/releases)
- [Changelog](https://github.com/node-red/node-red/blob/master/CHANGELOG.md)
- [Commits](node-red/node-red@3.1.15...4.1.6)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.1.1
  dependency-type: indirect
- dependency-name: node-red
  dependency-version: 4.1.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-133bf8486c branch from 90ae20e to 35091fb Compare March 10, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants