chore(deps): update js-yaml for CVE-2026-59870 - #515
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 32532e81-bc98-4bbe-b1a0-9172e33431b2
d810f0c
into
microsoft:master
🛰️ PR Sweeper reportRisk: 🟢 LOW · Security gate: ✅ passing · Files: 2 🔒 Automated guardrails (authoritative)No secret, PII, file-policy, or scope issues detected. ✅ 🤖 Dual-model AI review (advisory)AI review unavailable for this run (models not reachable or no diff). Guardrails above are unaffected.
The automated guardrails are authoritative and gate the security status. The AI review is advisory and never auto-merges. Thanks for contributing to FastTrack! 🛩️ |
Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com
Category
Related Issues
Resolves Dependabot alert #155 for CVE-2026-59870 (GHSA-5p4m-2wfm-xmqj).
What's in this Pull Request?
Updates the direct
js-yamldependency to 5.2.3 andgray-matter's transitive dependency from vulnerable 3.15.0 to the first patched 3.x release, 3.15.1.Validation
npm audit --audit-level=highreports 0 vulnerabilities; before the update it identified GHSA-5p4m-2wfm-xmqj.npm run checkvalidates all 30 catalog resources.