Skip to content

chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /site - #351

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/site/js-yaml-5.2.3
Closed

chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /site#351
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/site/js-yaml-5.2.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 5.2.2 to 5.2.3.

Changelog

Sourced from js-yaml's changelog.

[5.2.3] - 2026-08-01

Fixed

  • Prevent prototype fallback when resolving tags and mapping entries, #782.
  • Resolve !!timestamp years 0000-0099 correctly, #775.
  • Preserve implicit null mapping values before document markers and reject unpaired mapping event streams, #784.
  • Preserve folded scalar values with tab-indented lines when round-tripping a parsed AST through present(); dump() and loading are unaffected, #780.
Commits
  • 6740445 5.2.3 released
  • 94e766d Update changelog
  • c3bd7ca Polish previous commit, #780
  • 00209b6 presenter: treat a tab-indented line in a folded scalar as more-indented (#780)
  • 40fcb4f Fix missing mapping values before document markers and reject unpaired mappin...
  • 49280f3 Fix !!timestamp resolution for years 0000-0099, #775
  • 355dc96 fix: prevent prototype fallback in tag and harden object lookups, #782 (than...
  • d524f83 docs: add contributing guidelines
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.2 to 5.2.3.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.2.2...5.2.3)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
azchin added a commit that referenced this pull request Aug 10, 2026
Rolls up the open Dependabot PRs into one branch and closes every
Dependabot security alert that has a published fix.

Security alerts closed:
- GitPython 3.1.57 -> 3.1.58 (GHSA-hmq2-w58f-27jc, GHSA-jm78-9fvv-mhgr,
  GHSA-wvpp-8hx9-p66j, GHSA-hh9p-6wh2-4mfc, GHSA-9rj7-rf2p-w77r,
  GHSA-4gmw-gg2m-w46p) - PR #354
- brace-expansion 1.1.16 -> 1.1.18 (GHSA-mh99-v99m-4gvg) - PR #355
- fast-uri 3.1.4 -> 3.1.5 (GHSA-7p8r-x3mc-p8w7) - PR #352

Also fixed from `npm audit` in /site (no Dependabot alert filed):
- js-yaml 4.3.0 -> 4.3.1 in the nested docusaurus/cosmiconfig copies
  (GHSA-5p4m-2wfm-xmqj)
- nanoid 3.3.16 -> 3.3.18 (GHSA-2v37-7h3g-55p8)
- uuid 8.3.2 -> 11.1.1 via a package.json override; sockjs pins ^8.3.2
  and cannot be bumped on its own (GHSA-w5hq-g745-h8pq). sockjs only
  calls `require('uuid').v4`, which uuid 11 still exports from CJS, and
  it is reached only through webpack-dev-server.

Non-security bumps:
- js-yaml 5.2.2 -> 5.2.3 - PR #351
- react, react-dom 19.2.7 -> 19.2.8 - PR #350
- fastapi >=0.140.13 -> >=0.141.1, uvicorn >=0.51.0 -> >=0.52.0 in the
  builder and runner sidecars - PRs #349, #348

Verified: `uv lock --check` clean, `npm run build` succeeds, 587 unit
tests pass.

Signed-off-by: Andrew Chin <achin34@gatech.edu>
@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like js-yaml is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 10, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/site/js-yaml-5.2.3 branch August 10, 2026 19:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants