Skip to content

fix: js-yaml security vulnerability #8

Merged
GhostTypes merged 2 commits intomainfrom
claude/fix-security-vulnerability-01A9CvkzxGpujPDrmDX3jcyy
Nov 21, 2025
Merged

fix: js-yaml security vulnerability #8
GhostTypes merged 2 commits intomainfrom
claude/fix-security-vulnerability-01A9CvkzxGpujPDrmDX3jcyy

Conversation

@GhostTypes
Copy link
Copy Markdown
Member

Also adds an automated workflow to run tests on PRs

- Updated js-yaml from 3.14.1 to 3.14.2 to fix prototype pollution vulnerability (GHSA-mh29-5h37-fv8m)
- Updated brace-expansion from 1.1.11 to 1.1.12 and 2.0.1 to 2.0.2 to fix ReDoS vulnerability (GHSA-v6h2-p8h4-qcjw)

All 107 tests pass with no breaking changes.
- Runs tests on all pull requests and pushes
- Uses Node.js 20 with npm caching for faster builds
- Verifies both tests and build pass before allowing merge
- Acts as a required check for pull request approval
@GhostTypes GhostTypes self-assigned this Nov 21, 2025
@GhostTypes GhostTypes merged commit 59fea60 into main Nov 21, 2025
2 checks passed
@GhostTypes GhostTypes deleted the claude/fix-security-vulnerability-01A9CvkzxGpujPDrmDX3jcyy branch November 21, 2025 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants