Skip to content

build(deps): bump js-yaml from 3.15.0 to 3.15.2 - #484

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-3.15.1
Aug 27, 2026
Merged

build(deps): bump js-yaml from 3.15.0 to 3.15.2#484
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/js-yaml-3.15.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 3.15.0 to 3.15.2.

Changelog

Sourced from js-yaml's changelog.

3.15.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.

3.15.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 26, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 26, 2026 01:49
@dependabot
dependabot Bot requested review from Origin-Slakman and removed request for a team August 26, 2026 01:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 26, 2026
@github-actions
github-actions Bot removed the request for review from Origin-Slakman August 26, 2026 01:49
@github-actions

Copy link
Copy Markdown

✔️ If all status checks pass, and no other reviews are submitted, mergeabot will merge this PR the next time it runs.

As long as that's OK, no other action is necessary.

@dependabot dependabot Bot changed the title build(deps): bump js-yaml from 3.15.0 to 3.15.1 build(deps): bump js-yaml from 3.15.0 to 3.15.2 Aug 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.1 branch 2 times, most recently from ccde820 to 149feda Compare August 26, 2026 21:10
@github-actions
github-actions Bot enabled auto-merge (rebase) August 27, 2026 01:55
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.15.0 to 3.15.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.15.0...3.15.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.1 branch from 149feda to 67b8ffe Compare August 27, 2026 01:58
@github-actions
github-actions Bot merged commit d125d74 into main Aug 27, 2026
3 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/js-yaml-3.15.1 branch August 27, 2026 02:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants