Skip to content

v0.2.8 — js-yaml security patch + CI maintenance

Choose a tag to compare

@jaypetez jaypetez released this 14 Sep 04:57
· 22 commits to main since this release
7a09a93

Security and CI maintenance release. No runtime behaviour changed — every change is confined to the dev toolchain and the workflow pins.

Fixed

  • js-yaml advisory GHSA-2883-xcg3-v3hh (high). The js-yaml@4 override pinned ^4.3.1 and the lockfile resolved to exactly 4.3.1 — inside the vulnerable range (>=4.0.0 <4.3.2). Both override lines now pin the patched versions (js-yaml@4 → ^4.3.2, js-yaml@3 → ^3.15.2).

    js-yaml reaches the tree transitively via @commitlint/cli > @commitlint/load > cosmiconfig, and Dependabot's security-update job runs with update-subdependencies: false, so Dependabot could not fix this itself — its run errored out and the override had to be bumped by hand.

    The advisory was failing the audit job, which fails the aggregate build gate — the single required check on main — and so had the entire Dependabot queue blocked. (#98)

Changed

  • CI actions: pnpm/action-setup 6.0.10 → 6.1.0 (#96) and changesets/action 2.1.1 → 2.1.2 (#97). The latter is patch-only (no input renames), so the pin's documented lockstep with @changesets/cli v3 still holds.

Full changelog: v0.2.7...v0.2.8