chore(deps): bump js-yaml 4.3.2 and baseline-browser-mapping 2.11.22 - #44
Conversation
Clear Dependabot alert #71 / GHSA-2883-xcg3-v3hh (CVE-2026-84375) without a markdownlint-cli2 major upgrade.
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: 3 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🔇 Additional comments (1)
📝 WalkthroughWalkthroughThe package configuration updates the ChangesDependency override
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The dependency override and lockfile are reported as aligned, with no remaining merge-blocking concerns. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches✨ Simplify code
Comment |
Description
Dependabot alert #71 is open for
js-yaml4.3.1 (GHSA-2883-xcg3-v3hh / CVE-2026-84375, high). There is no Dependabot PR for it. The existing npm override still pinned 4.3.1.Dependabot #43 also bumped transitive
baseline-browser-mapping2.10.38 → 2.11.22, then conflicted after #42 mergedbrowserslistand left the lockfile on 2.11.21. Dependabot later closed #43 as "up-to-date"; this PR reapplies 2.11.22 onto current main so that bump is not lost.Type of Change
Changes Made
package.jsonoverrides:js-yaml4.3.1 → 4.3.2 (alert #71)package-lock.json: hoistjs-yaml@4.3.2; bumpbaseline-browser-mapping2.11.21 → 2.11.22 (reapply Bump baseline-browser-mapping from 2.10.38 to 2.11.22 #43)Major-version judgment
Not required. Both are patches on already-used 4.x / 2.11.x lines.
markdownlint-cli2stays on 0.20.0.Testing Done
npm test(11/11 passed)npm run lint(js/css/md clean)npm cifrom the js-yaml lockfile: everyjs-yamledge is 4.3.2js-yaml@4.3.2andbaseline-browser-mapping@2.11.22match the lockfilebundle exec jekyll serve(Ruby/Bundler not installed in this agent image)Related Issues
Addresses Dependabot alert #71. Supersedes Dependabot #43. #42 is already merged and is not reopened.
Checklist
Additional Notes
Left nanoid (high) and colord (moderate) unfixed: they are not alert #71 and have no open Dependabot PRs. Deploy is expected to skip on PR; Actions is the merge gate. Do not squash.
Summary by CodeRabbit