Skip to content

chore(deps): override yaml to ^2.8.3 (security advisory)#1

Merged
flippelt merged 1 commit into
mainfrom
chore/yaml-override
Jun 4, 2026
Merged

chore(deps): override yaml to ^2.8.3 (security advisory)#1
flippelt merged 1 commit into
mainfrom
chore/yaml-override

Conversation

@flippelt
Copy link
Copy Markdown
Owner

@flippelt flippelt commented Jun 4, 2026

Forces the transitive yaml (via @astrojs/check → yaml-language-server) up to >=2.8.3 to clear the security advisory Dependabot couldn't auto-fix. Resolves to 2.9.0; astro check + build verified green. Dev-only tooling.

🤖 Generated with Claude Code

yaml came in transitively via @astrojs/check -> yaml-language-server@1.20.0 (pinned 2.7.1); Dependabot couldn't bump it (security_update_not_possible). An npm override forces yaml >=2.8.3 (resolves to 2.9.0). astro check + build verified green. @astrojs/check is dev-only (type-check), so this is build-tooling only.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@flippelt flippelt merged commit 8deedbb into main Jun 4, 2026
1 check passed
@flippelt flippelt deleted the chore/yaml-override branch June 4, 2026 01:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant