Repository navigation
v0.2.8 — js-yaml security patch + CI maintenance
Security and CI maintenance release. No runtime behaviour changed — every change is confined to the dev toolchain and the workflow pins.
Fixed
-
js-yamladvisory GHSA-2883-xcg3-v3hh (high). Thejs-yaml@4override pinned^4.3.1and the lockfile resolved to exactly 4.3.1 — inside the vulnerable range (>=4.0.0 <4.3.2). Both override lines now pin the patched versions (js-yaml@4→^4.3.2,js-yaml@3→^3.15.2).js-yamlreaches the tree transitively via@commitlint/cli > @commitlint/load > cosmiconfig, and Dependabot's security-update job runs withupdate-subdependencies: false, so Dependabot could not fix this itself — its run errored out and the override had to be bumped by hand.The advisory was failing the
auditjob, which fails the aggregatebuildgate — the single required check onmain— and so had the entire Dependabot queue blocked. (#98)
Changed
- CI actions:
pnpm/action-setup6.0.10 → 6.1.0 (#96) andchangesets/action2.1.1 → 2.1.2 (#97). The latter is patch-only (no input renames), so the pin's documented lockstep with@changesets/cliv3 still holds.
Full changelog: v0.2.7...v0.2.8