Skip to content

Commit afe68fb

Browse files
committed
fix(deps): bump js-yaml 3.15.1 / 4.3.1 and mermaid 11.16.1 for the OSV advisory wave (#6088)
Targeted lockfile-only re-resolution clearing all 7 advisories that turned `Validate Package Dependencies` red on every PR whose diff touches a dependency file: GHSA-5p4m-2wfm-xmqj (7.5 High) js-yaml 3.15.0 -> 3.15.1 GHSA-5p4m-2wfm-xmqj (7.5 High) js-yaml 4.3.0 -> 4.3.1 GHSA-2v8p-3f2j-5mp7 (5.3) mermaid 11.16.0 -> 11.16.1 GHSA-3rrr-jr9j-h3q3 (6.5) mermaid 11.16.0 -> 11.16.1 GHSA-6x64-9x62-f2gx (5.3) mermaid 11.16.0 -> 11.16.1 GHSA-c4c3-pg64-4m4v (2.4) mermaid 11.16.0 -> 11.16.1 GHSA-rhh3-jpg6-66xh (5.3) mermaid 11.16.0 -> 11.16.1 All three fixed versions are patch releases inside the ranges their parents already declare (read-yaml-file js-yaml@^3.6.1, @changesets/parse js-yaml@^4.1.1, apps/docs mermaid@^11.16.0) and carry byte-identical dependency sets, so no manifest, override or changeset is needed. js-yaml@5.2.2 (packages/metadata, not flagged) is deliberately untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wbxm29qPKnLf44AbSxizqW
1 parent e3ef52b commit afe68fb

1 file changed

Lines changed: 12 additions & 12 deletions

File tree

pnpm-lock.yaml

Lines changed: 12 additions & 12 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)