Skip to content

Bump js-yaml from 4.1.0 to 4.1.1#5

Merged
arcanistzed merged 1 commit intomainfrom
dependabot/npm_and_yarn/js-yaml-4.1.1
Apr 12, 2026
Merged

Bump js-yaml from 4.1.0 to 4.1.1#5
arcanistzed merged 1 commit intomainfrom
dependabot/npm_and_yarn/js-yaml-4.1.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Nov 16, 2025

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps js-yaml from 4.1.0 to 4.1.1.

Changelog

Sourced from js-yaml's changelog.

[4.1.1] - 2025-11-12

Security

  • Fix prototype pollution issue in yaml merge (<<) operator.
Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 16, 2025
@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages bot commented Nov 16, 2025

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
101week-contracts 1d36841 Commit Preview URL

Branch Preview URL
Apr 12 2026, 10:14 PM

@arcanistzed
Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.0 to 4.1.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.1.0...4.1.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js-yaml-4.1.1 branch from 050c0e2 to 1d36841 Compare April 12, 2026 22:10
@arcanistzed arcanistzed merged commit 9e05d82 into main Apr 12, 2026
1 check passed
@arcanistzed arcanistzed deleted the dependabot/npm_and_yarn/js-yaml-4.1.1 branch April 12, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant