Skip to content

Fix Dependabot security alerts: replace serde_yml, update npm deps#22

Merged
ewels merged 1 commit into
mainfrom
fix-security
Mar 3, 2026
Merged

Fix Dependabot security alerts: replace serde_yml, update npm deps#22
ewels merged 1 commit into
mainfrom
fix-security

Conversation

@ewels
Copy link
Copy Markdown
Member

@ewels ewels commented Mar 3, 2026

Summary

Changes

File Change
Cargo.toml serde_yml = "0.0.12"serde_yaml_ng = "0.10"
src/config.rs serde_yml::from_strserde_yaml_ng::from_str (9 call sites)
Cargo.lock Updated lockfile (removes serde_yml + libyml, adds serde_yaml_ng + unsafe-libyaml)
docs/package-lock.json Updated transitive deps to patched versions

Verification

  • All 151 tests pass (139 unit + 12 integration)
  • cargo clippy -- -D warnings clean
  • cargo fmt --check clean
  • npm audit reports 0 vulnerabilities

@ewels ewels merged commit 61ff100 into main Mar 3, 2026
4 checks passed
@ewels ewels deleted the fix-security branch March 3, 2026 22:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant