Skip to content

Conversation

@MattiJarvinen
Copy link
Contributor

xmlbuilder2 versions 2.3.0 - 3.1.1 depends on vulnerable versions of js-yaml ( <3.14.2 ). This caused npm audit moderate warning: GHSA-mh29-5h37-fv8m

PR Checklist

Closes #1981

What is the new behavior?

None. No audit errors due to this.

Does this PR introduce a breaking change?

  • Yes
  • No

[optional] What gif best describes this PR or how it makes you feel?

BackToTheFutureMartyMcflyGIF

xmlbuilder2 versions 2.3.0 - 3.1.1 depends on vulnerable versions of
js-yaml ( <3.14.2 ). This caused npm audit moderate warning:
GHSA-mh29-5h37-fv8m
@netlify
Copy link

netlify bot commented Nov 26, 2025

Deploy Preview for analog-blog ready!

Name Link
🔨 Latest commit 49ffa8c
🔍 Latest deploy log https://app.netlify.com/projects/analog-blog/deploys/692737242385eb00086cc456
😎 Deploy Preview https://deploy-preview-1982--analog-blog.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify
Copy link

netlify bot commented Nov 26, 2025

Deploy Preview for analog-app ready!

Name Link
🔨 Latest commit 49ffa8c
🔍 Latest deploy log https://app.netlify.com/projects/analog-app/deploys/6927372434975700084dada3
😎 Deploy Preview https://deploy-preview-1982--analog-app.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify
Copy link

netlify bot commented Nov 26, 2025

Deploy Preview for analog-docs ready!

Name Link
🔨 Latest commit 49ffa8c
🔍 Latest deploy log https://app.netlify.com/projects/analog-docs/deploys/69273724f2e19900082bf552
😎 Deploy Preview https://deploy-preview-1982--analog-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@brandonroberts brandonroberts merged commit 0bb32a6 into analogjs:beta Nov 27, 2025
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Npm audit vulnerability due to xmlbuilder2 -> js-yaml < 3.14.2

2 participants