Skip to content

[0.80] Bump js-yaml 3.14.1 to 3.14.2 & js-yaml from 4.1.0 to 4.1.1 for component governance#15464

Merged
HariniMalothu17 merged 4 commits intomicrosoft:0.80-stablefrom
HariniMalothu17:cg_Upgradejs_yaml_0.80
Feb 9, 2026
Merged

[0.80] Bump js-yaml 3.14.1 to 3.14.2 & js-yaml from 4.1.0 to 4.1.1 for component governance#15464
HariniMalothu17 merged 4 commits intomicrosoft:0.80-stablefrom
HariniMalothu17:cg_Upgradejs_yaml_0.80

Conversation

@HariniMalothu17
Copy link
Contributor

@HariniMalothu17 HariniMalothu17 commented Dec 8, 2025

Description

Upgraded following packages
js-yaml 3.14.1 to 3.14.2
js-yaml from 4.1.0 to 4.1.1

Type of Change

  • Bug fix (non-breaking change which fixes an issue)

Why

Upgraded to js-yaml to fix security vulnerabilities

Resolves #15457 #15458

What

Updated the yarn.lock to point to the new versions.

Steps to upgrade:

Delete the older version from yarn.lock file
Execute yarn command so it can fetch the new versions.

Screenshots

image

Changelog

Should this change be included in the release notes: indicate :no

Microsoft Reviewers: Open in CodeFlow
Microsoft Reviewers: Open in CodeFlow
Microsoft Reviewers: Open in CodeFlow

@HariniMalothu17 HariniMalothu17 requested a review from a team as a code owner December 8, 2025 10:34
@HariniMalothu17 HariniMalothu17 marked this pull request as draft December 9, 2025 06:50
@HariniMalothu17 HariniMalothu17 self-assigned this Dec 16, 2025
@HariniMalothu17 HariniMalothu17 marked this pull request as ready for review February 9, 2026 10:05
@HariniMalothu17 HariniMalothu17 enabled auto-merge (squash) February 9, 2026 10:15
@HariniMalothu17 HariniMalothu17 merged commit 2f236bf into microsoft:0.80-stable Feb 9, 2026
91 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants