Skip to content

chore(deps): bump js-yaml from 4.3.1 to 5.2.3 - #12345

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-5.2.3
Closed

chore(deps): bump js-yaml from 4.3.1 to 5.2.3#12345
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-5.2.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.1 to 5.2.3.

Changelog

Sourced from js-yaml's changelog.

[5.2.3] - 2026-08-01

Fixed

  • Prevent prototype fallback when resolving tags and mapping entries, #782.
  • Resolve !!timestamp years 0000-0099 correctly, #775.
  • Preserve implicit null mapping values before document markers and reject unpaired mapping event streams, #784.
  • Preserve folded scalar values with tab-indented lines when round-tripping a parsed AST through present(); dump() and loading are unaffected, #780.

[5.2.2] - 2026-07-24

Fixed

  • Quote flow scalars where a colon precedes a flow indicator, #773.

Security

  • Avoid exponential parsing time for nested flow sequence pairs.

[5.2.1] - 2026-07-02

Fixed

  • Add Map support to !!omap (should work when realMapTag used)

Security

  • Remove quadratic complexity from !!omap addItem. Regression from v5 (usually not critical, because YAML11_SCHEMA is not default anymore).

4.3.0, 3.15.0 - 2026-06-27

Security

  • Backported maxTotalMergeKeys option.

[5.2.0] - 2026-06-26

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.
  • Added maxAliases (-1) loader option to limit the number of YAML aliases per document.

Removed

  • maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.

Fixed

  • Round-trip of integers with exponential form (>= 1e21)

[5.1.0] - 2026-06-23

... (truncated)

Commits
  • 6740445 5.2.3 released
  • 94e766d Update changelog
  • c3bd7ca Polish previous commit, #780
  • 00209b6 presenter: treat a tab-indented line in a folded scalar as more-indented (#780)
  • 40fcb4f Fix missing mapping values before document markers and reject unpaired mappin...
  • 49280f3 Fix !!timestamp resolution for years 0000-0099, #775
  • 355dc96 fix: prevent prototype fallback in tag and harden object lookups, #782 (than...
  • d524f83 docs: add contributing guidelines
  • 3c29559 5.2.2 released
  • 3e5240f parser: avoid reparsing flow sequence pair keys
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 10, 2026
@mergify
mergify Bot had a problem deploying to Mergify Merge Protections August 10, 2026 06:21 Failure
@mergify

mergify Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Merge Protections

🔴 1 of 6 protections blocking · waiting on 🤖 CI and 🙋 you

Protection Waiting on
🔴 🤖 Continuous Integration 🤖 CI and 🙋 you
🟢 👀 Review Requirements
🟢 Enforce conventional commit
🟢 🔎 Reviews
🟢 📕 PR description
🟢 🚦 Auto-queue

🔴 🤖 Continuous Integration

Waiting for

  • check-success = build
  • check-success = lint
  • check-success = test
  • any of:
    • check-success = test-broken-links
    • label = ignore-broken-links
This rule is failing.
  • all of:
    • check-success = build
    • check-success = lint
    • check-success = test
    • any of:
      • check-success = test-broken-links
      • label = ignore-broken-links
    • any of:
      • check-success=Cloudflare Pages
      • -head-repo-full-name~=^Mergifyio/

Show 5 satisfied protections

🟢 👀 Review Requirements

  • any of:
    • author = dependabot[bot]
    • #approved-reviews-by >= 2
    • all of:
      • author = mergify-ci-bot
      • -head ~= ^docs-agent/

🟢 Enforce conventional commit

Make sure that we follow https://www.conventionalcommits.org/en/v1.0.0/

  • title ~= ^(fix|feat|internal|docs|style|refactor|perf|test|build|ci|chore|revert|ui)(?:\(.+\))?!?:

🟢 🔎 Reviews

  • #changes-requested-reviews-by = 0
  • #review-requested = 0
  • #review-threads-unresolved = 0

🟢 📕 PR description

  • body ~= (?ms:.{48,})

🟢 🚦 Auto-queue

When all merge protections are satisfied, this pull request will be queued automatically.

@mergify

mergify Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

@dependabot[bot] this pull request is now in conflict 😩

@mergify mergify Bot added the conflict label Aug 10, 2026
@dependabot dependabot Bot changed the title chore(deps): bump js-yaml from 4.3.0 to 5.2.3 chore(deps): bump js-yaml from 4.3.1 to 5.2.3 Aug 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-5.2.3 branch from 81cfe97 to a2a0605 Compare August 10, 2026 06:27
@mergify
mergify Bot had a problem deploying to Mergify Merge Protections August 10, 2026 06:27 Failure
@mergify mergify Bot removed the conflict label Aug 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-5.2.3 branch from a2a0605 to f7112ab Compare August 10, 2026 06:39
@mergify
mergify Bot had a problem deploying to Mergify Merge Protections August 10, 2026 06:40 Failure
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 5.2.3.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...5.2.3)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-5.2.3 branch from f7112ab to e659d28 Compare August 17, 2026 06:51
@mergify
mergify Bot had a problem deploying to Mergify Merge Protections August 17, 2026 06:51 Failure
@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #12492.

@dependabot dependabot Bot closed this Aug 24, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/js-yaml-5.2.3 branch August 24, 2026 06:32
mergify Bot pushed a commit that referenced this pull request Aug 24, 2026
Supersedes #12345, which only moves the version and so is red on `build`,
`lint`, `test` and `config-examples`. v5 is a breaking release and the two
call sites have to move with it.

`scripts/validate-config-examples.mjs` now imports js-yaml as a namespace.
v5 dropped the CommonJS default export, so `import yaml from 'js-yaml'` failed
to load at all. That was also behind the three test failures: `yaml` was
`undefined`, `yaml.load` threw a `TypeError`, the script caught it and reported
"invalid YAML", so an example that should have failed AJV schema validation
failed at the parse step instead. All three pass on the import fix alone — no
v5 parsing behaviour change is involved.

`OptionsTable.tsx` drops `noCompatMode: true`, which v5 removed. It suppressed
YAML-1.1-compat quoting of `yes`/`no`/`on`/`off` and base-60 values. None of
the 136 defaults in the schema are one of those, so this is a no-op today; v5
quotes them by default and offers no way to opt out, so a future default of
`no` would start rendering as `"no"`.

`OptionsTable.tsx` also renames `quotingType: '"'` to `quoteStyle: 'double'`,
and this is the reason the bump is not mechanical. v5 renamed that option *and*
flipped its default to `'single'`, so just deleting the two options `tsc`
rejects silently reflows four published defaults. The worst is
`post_check.title`, whose value contains single quotes:

    before  "'{{ check_rule_name }}'{% if check_status == 'success' %} …"
    after   '''{{ check_rule_name }}''{% if check_status == ''success'' %} …'

Equivalent YAML, unreadable in a table people copy-paste from.

`@types/js-yaml` is dropped rather than bumped: v5 ships its own types, so the
stub is now a mismatched duplicate.

This goes to 5.3.0 rather than the 5.2.3 in #12345 because `^5.2.3` resolves to
5.3.0 anyway, and 5.3.0 only adds a custom-tag API this repo does not touch —
`dump` output is byte-identical between the two.

Verification: built the site on `main` and on this branch and diffed the
output — all 385 pages are byte-identical, so nothing readers see moves. Every
schema default also renders identically through `dumpDefault`. `pnpm check`,
`pnpm test` (172), `pnpm check:config-examples` (122 examples) and
`pnpm check:internal-leaks` are green, and a full build with OG generation on
produces 137 cards, same as `main`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Development

Successfully merging this pull request may close these issues.

0 participants