From 140f0acc1d276e23f6379990a561656b95dff35e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 18 Nov 2025 10:21:51 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-13961110 --- package-lock.json | 9 +++++---- package.json | 2 +- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index b62cb40..d12a429 100644 --- a/package-lock.json +++ b/package-lock.json @@ -114,7 +114,7 @@ "jest-watcher": "^29.5.0", "jest-worker": "^29.5.0", "js-tokens": "^4.0.0", - "js-yaml": "^3.14.1", + "js-yaml": "^3.14.2", "jsesc": "^2.5.2", "json-parse-even-better-errors": "^2.3.1", "json5": "^2.2.3", @@ -4243,9 +4243,10 @@ "integrity": "sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==" }, "node_modules/js-yaml": { - "version": "3.14.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.1.tgz", - "integrity": "sha512-okMH7OXXJ7YrN9Ok3/SXrnu4iX9yOk+25nqX4imS2npuvTYDmo/QEZoqwZkYaIDk3jVvBOTOIEgEhaLOynBS9g==", + "version": "3.14.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", + "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", + "license": "MIT", "dependencies": { "argparse": "^1.0.7", "esprima": "^4.0.0" diff --git a/package.json b/package.json index d5dcde8..9e92391 100644 --- a/package.json +++ b/package.json @@ -141,7 +141,7 @@ "jest-watcher": "^29.5.0", "jest-worker": "^29.5.0", "js-tokens": "^4.0.0", - "js-yaml": "^3.14.1", + "js-yaml": "^3.14.2", "jsesc": "^2.5.2", "json-parse-even-better-errors": "^2.3.1", "json5": "^2.2.3",