Skip to content

chore(deps): bump js-yaml from 4.3.1 to 4.3.2 in /lua-employee-onboarding - #73

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.3.1 to 4.3.2.

Changelog

Sourced from js-yaml's changelog.

4.3.2 - 2026-08-26

Changed

  • [backport] Hard-limit merge sequence size to 100.

Security

  • [backport] Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.
Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 13, 2026
@dependabot
dependabot Bot requested a review from a team September 13, 2026 09:58
@dependabot dependabot Bot added javascript Pull requests that update javascript code dependencies Pull requests that update a dependency file labels Sep 13, 2026

@johnmicheal-lua johnmicheal-lua left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport that limits merge-sequence size and counts empty mappings toward maxTotalMergeKeys to mitigate CPU-exhaustion. Both package.json and package-lock.json are updated consistently, the new integrity hash is present, and there are no source or API changes. Safe to merge once CI passes.


PR Risk Reviewer — automated senior review of 15da946 · risk: low · confidence: 0.96

richard-lua
richard-lua previously approved these changes Sep 13, 2026

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence CPU usage. The change is confined to package.json and package-lock.json, is semver-compatible with the existing ^4.3.1 range, and the lockfile version/integrity are consistent. Safe to merge once CI passes.


PR Risk Reviewer — automated senior review of 15da946 · risk: low · confidence: 0.95

selcuk-lua
selcuk-lua previously approved these changes Sep 13, 2026

@selcuk-lua selcuk-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2 in lua-employee-onboarding. The upstream release is a security-focused backport (hard-limits merge sequence size and counts empty mappings toward maxTotalMergeKeys to curb CPU usage). The package.json and package-lock.json changes are consistent — version, resolved URL, and integrity hash all match the 4.3.2 release — and there are no source changes.

The change looks solid: it is a patch-level, security-hardening upgrade with a matching lockfile update and minimal blast radius. Merge once CI is green.


PR Risk Reviewer — automated senior review of 15da946 · risk: low · confidence: 0.97

@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot can't resolve your JavaScript dependency files. Because of this, Dependabot cannot update this pull request.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot can't resolve your JavaScript dependency files. Because of this, Dependabot cannot update this pull request.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2 branch from 15da946 to d4f8e6f Compare September 15, 2026 17:47

@johnmicheal-lua johnmicheal-lua left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

No blocking findings were raised in the prior review; the earlier assessment (LOW risk) stands.

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence size and counting empty mappings toward maxTotalMergeKeys to mitigate CPU exhaustion. Both package.json and package-lock.json are updated consistently, the new integrity hash is present, and there are no source or API changes.

One operational note: Dependabot has posted that it "can't resolve your JavaScript dependency files," so confirm the lockfile installs cleanly in CI before merging. No code-level findings.


PR Risk Reviewer — automated senior review of d4f8e6f · risk: low · confidence: 0.95 · re-review · round 2

richard-lua
richard-lua previously approved these changes Sep 15, 2026

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Unchanged since the prior review: a routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2 (a security backport limiting merge-sequence CPU usage), confined to package.json and package-lock.json with consistent version/integrity. Safe to merge on its own merits — but note Dependabot commented it "can't resolve your JavaScript dependency files," so the lockfile may not fully resolve and CI/merge is currently blocked; verify the dependency graph installs cleanly before merging.

No blocking findings.


PR Risk Reviewer — automated senior review of d4f8e6f · risk: low · confidence: 0.95 · re-review · round 2

selcuk-lua
selcuk-lua previously approved these changes Sep 15, 2026

@selcuk-lua selcuk-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously flagged

No blocking findings were raised previously. The prior LOW-risk assessment stands.

Code review — LOW risk

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2. The upstream release is a security-hardening backport (hard-limits merge sequence size and counts empty mappings toward maxTotalMergeKeys). The package.json and package-lock.json changes are consistent — version, resolved URL, and integrity hash all match the 4.3.2 release — and there are no source changes.

One operational note: Dependabot commented that it "can't resolve your JavaScript dependency files," so confirm the lockfile actually resolves and CI is green before merging. Otherwise the change looks solid: patch-level, security-focused, minimal blast radius.


PR Risk Reviewer — automated senior review of d4f8e6f · risk: low · confidence: 0.96 · re-review · round 2

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2 branch from d4f8e6f to 1b81298 Compare September 18, 2026 12:36
richard-lua
richard-lua previously approved these changes Sep 18, 2026

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

  • Dependabot dependency-resolution warning — still open (advisory): Dependabot again commented it "can't resolve your JavaScript dependency files." Confirm the lockfile resolves and CI installs cleanly before merging.

Unchanged since prior rounds: a routine patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence CPU usage. Version and integrity hash in package-lock.json are consistent with package.json's ^4.3.2 range, and the change is semver-compatible. No new issues in these commits.

No blocking findings.


PR Risk Reviewer — automated senior review of 1b81298 · risk: low · confidence: 0.95 · re-review · round 3

selcuk-lua
selcuk-lua previously approved these changes Sep 18, 2026

@selcuk-lua selcuk-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously flagged

  • No blocking findings were raised in earlier rounds; the prior LOW-risk assessment stands.
  • Operational note (still open, advisory): Dependabot again reported it "can't resolve your JavaScript dependency files." Confirm the lockfile resolves cleanly and CI is green before merging.

Code review — LOW risk

Patch-level, security-hardening bump of js-yaml 4.3.1 → 4.3.2. The package.json and package-lock.json changes are consistent — version, resolved URL, and integrity hash all match the 4.3.2 release — with no source changes and minimal blast radius. Merge once CI is green, keeping in mind Dependabot's outstanding resolution warning.


PR Risk Reviewer — automated senior review of 1b81298 · risk: low · confidence: 0.96 · re-review · round 3

@johnmicheal-lua johnmicheal-lua left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

No blocking findings were raised in prior rounds; the earlier LOW-risk assessment stands.

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence size and counting empty mappings toward maxTotalMergeKeys to mitigate CPU exhaustion. Both manifest and lockfile are updated consistently, the integrity hash is present, and there are no source or API changes.

Operational note (unchanged): Dependabot reports it "can't resolve your JavaScript dependency files," so confirm the lockfile installs cleanly in CI before merging. No code-level findings.


PR Risk Reviewer — re-review · round 3 · risk: low


PR Risk Reviewer — automated senior review of 1b81298 · risk: low · confidence: 0.95 · re-review · round 3

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2 branch from 1b81298 to d21e497 Compare September 22, 2026 10:30

@johnmicheal-lua johnmicheal-lua left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

No blocking findings were raised in prior rounds; the earlier LOW-risk assessment stands.

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence size and counting empty mappings toward maxTotalMergeKeys to mitigate CPU exhaustion. Manifest and lockfile are updated consistently, the integrity hash is present, and there are no code changes. The PR is ready from a review standpoint.

Operational note (unchanged): Dependabot reports it "can't resolve your JavaScript dependency files," so confirm the lockfile installs cleanly in CI before merging. No code-level findings.


PR Risk Reviewer — re-review · round 4 · risk: low


PR Risk Reviewer — automated senior review of d21e497 · risk: low · confidence: 0.95 · re-review · round 4 (converged — no new blocking findings)

richard-lua
richard-lua previously approved these changes Sep 22, 2026

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

  • Dependabot dependency-resolution warning — still open (advisory): Dependabot repeated that it "can't resolve your JavaScript dependency files," and mergeable_state is blocked. Confirm the lockfile resolves and CI installs cleanly before merging; this is an environment/CI concern, not a defect in the change.

Unchanged since prior rounds: a routine patch bump of js-yaml 4.3.1 → 4.3.2, a security backport that hard-limits merge-sequence size and counts empty mappings toward maxTotalMergeKeys to bound CPU usage. The version and integrity hash in package-lock.json are consistent with package.json's ^4.3.2 range and the change is semver-compatible.

No blocking findings. The only open item is the Dependabot/CI resolution warning, which a human should confirm before merge.


PR Risk Reviewer — automated senior review of d21e497 · risk: low · confidence: 0.95 · re-review · round 4 (converged — no new blocking findings)

selcuk-lua
selcuk-lua previously approved these changes Sep 22, 2026

@selcuk-lua selcuk-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously flagged

  • No blocking findings were raised in earlier rounds; the prior LOW-risk assessment stands.
  • Operational note (still open, advisory): Dependabot again reported it "can't resolve your JavaScript dependency files." This blocks Dependabot from updating the PR automatically. Confirm the lockfile resolves cleanly and CI is green before merging.

Code review — LOW risk

Patch-level, security-hardening bump of js-yaml 4.3.1 → 4.3.2. The package.json and package-lock.json changes are consistent — version, resolved URL, and integrity hash all match the 4.3.2 release — with no source changes and minimal blast radius. Nothing blocking remains open; the only outstanding item is Dependabot's resolution warning, which is an operational/CI concern for a human to clear before merge.


PR Risk Reviewer — automated senior review of d21e497 · risk: low · confidence: 0.96 · re-review · round 4


PR Risk Reviewer — automated senior review of d21e497 · risk: low · confidence: 0.96 · re-review · round 4 (converged — no new blocking findings)

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lua-employee-onboarding/js-yaml-4.3.2 branch from d21e497 to e54d36a Compare September 24, 2026 07:16

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

  • Dependabot dependency-resolution warning — still open (advisory): Dependabot again reports it "can't resolve your JavaScript dependency files." This is a CI/environment concern, not a defect in the change. Confirm the lockfile resolves and CI installs cleanly before merging.

Unchanged since prior rounds: a routine patch bump of js-yaml 4.3.1 → 4.3.2 — a security backport that hard-limits merge-sequence size and counts empty mappings toward maxTotalMergeKeys to bound CPU usage. The version and integrity hash in package-lock.json are consistent with package.json's ^4.3.2 range, and the change is semver-compatible.

No blocking findings. The only open item is the Dependabot/CI resolution warning, which a human should confirm before merge.


PR Risk Reviewer — round 5 (converged — no new blocking findings)


PR Risk Reviewer — automated senior review of e54d36a · risk: low · confidence: 0.95 · re-review · round 5 (converged — no new blocking findings)

@selcuk-lua selcuk-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously flagged

  • No blocking findings were raised in earlier rounds; the prior LOW-risk assessment stands.
  • Operational note (still open, advisory): Dependabot again reports it "can't resolve your JavaScript dependency files," so it cannot auto-update this PR. Confirm the lockfile resolves cleanly and CI is green before merging. This is a CI/operational concern for a human, not a code defect.

Code review — LOW risk

Patch-level, security-hardening bump of js-yaml 4.3.1 → 4.3.2. The package.json and package-lock.json changes are consistent — version, resolved URL, and integrity hash all match the 4.3.2 release — with no source changes and minimal blast radius. Nothing blocking remains open; the only outstanding item is Dependabot's resolution warning. The PR is ready to merge once CI is green.


PR Risk Reviewer — round 5 (converged — no new blocking findings)


PR Risk Reviewer — automated senior review of e54d36a · risk: low · confidence: 0.96 · re-review · round 5 (converged — no new blocking findings)

@johnmicheal-lua johnmicheal-lua left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

Previously flagged

No blocking findings were raised in prior rounds; the earlier LOW-risk assessment stands.

Routine Dependabot patch bump of js-yaml 4.3.1 → 4.3.2, a security backport limiting merge-sequence size and counting empty mappings toward maxTotalMergeKeys to mitigate CPU exhaustion. Manifest and lockfile are updated consistently, the integrity hash is present, and there are no source or API changes. The PR is ready from a review standpoint.

Operational note (unchanged): Dependabot reports it "can't resolve your JavaScript dependency files," so confirm the lockfile installs cleanly in CI before merging. No code-level findings.


PR Risk Reviewer — automated senior review of e54d36a · risk: low · confidence: 0.95 · re-review · round 5 (converged — no new blocking findings)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants