Repository navigation
[dependabot-agent] Bump yaml from 2.9.0 to 2.9.1 - #11463
cao-githubnext-gh-aw-cao-write[bot] wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dashboard view assessment5/6 selected views passed the informational assessment. The DOM budget is 6000 nodes per loaded view.
|
|
Duplicate detected. This PR duplicates three other open dependabot-agent PRs that already propose the identical
No further action needed from the automation side until a maintainer consolidates these.
|
What changed
gh-aw-caopackage)package.json,package-lock.jsonyaml@2.9.0yaml@2.9.1Why now
yamlwas one minor patch behind.npm auditreports 0 vulnerabilities at 2.9.0, and both known GHSA advisories foryaml(GHSA-48c2-rrv3-qjmp / CVE-2026-33532 stack-overflow-via-deep-nesting, and GHSA-f9xv-q969-pqx4 / CVE-2023-2251) were already patched at 2.8.3 and 2.2.2 respectively — well before 2.9.0. This is not a security-driven update.yamlis a direct root dependency imported across test files (tests/unit/*.test.mjs),dashboard/site/src/validator.js,scripts/package-lifecycle-matrix.mjs, anddocs/lib/catalog.ts, so keeping it current avoids drift.Risk assessment
import { parse } from "yaml"/parseAllDocuments) in 6+ files; confirmed via repository grep.Validation
npm install yaml@2.9.1,npm run test:unit, manual smoke test ofparse()/parseAllDocumentsvianode -e.main(same commands, same sandbox) — confirmed viagit stash/git stash popA/B comparison. The failing tests are pre-existing, environment-dependent (network/credential-gated) and unrelated to this change; none referenceyamlparsing.yaml.parse/parseAllDocumentssmoke-tested successfully.npm run check(lint/typecheck/compile/docs build) not run in this pass; recommend CI confirms green before merge.Control Plane
Toolchain: Node v22.23.2 (as preinstalled in sandbox), npm resolving via existing
package-lock.jsonmirror configuration (no toolchain manifest change needed).Registry preflight:
npm view yaml@2.9.1resolved successfully from the public npm registry; no private registry involved.Breaking changes/migrations: none — patch-level release, no documented breaking API changes.
Risk: low
Confidence: high
Rollback: revert this commit (or pin
yamlback to2.9.0inpackage.jsonand regeneratepackage-lock.jsonwithnpm install yaml@2.9.0).Smart-Dependabot-Merge-Candidate: yes
Reviewer checklist
Rollback guidance
yamlback to2.9.0inpackage.jsonand runnpm install yaml@2.9.0to regeneratepackage-lock.json.package.jsonandpackage-lock.jsontogether; they must stay in sync.