Skip to content

Fix 'js-yaml has prototype pollution in merge' alert#3770

Merged
SriHV merged 4 commits intomainfrom
fix-js-yaml-security-vulnerability
Jan 13, 2026
Merged

Fix 'js-yaml has prototype pollution in merge' alert#3770
SriHV merged 4 commits intomainfrom
fix-js-yaml-security-vulnerability

Conversation

@SriHV
Copy link
Copy Markdown
Contributor

@SriHV SriHV commented Dec 18, 2025

What is the context of this PR?

ONSDESYS-761

Updated jest, puppeteer, babel-plugin-istanbul and style-lint to latest versions to js-yaml issue

Also @babel/core, babel/plugin-transform-runtime, @babel/preset-env, @babel/runtime as latest version of jest required the latest version of these libraries.

Also updated tests puppeteer.spec.js

How to review this PR

Describe the steps required to test the changes (include screenshots if appropriate).

Checklist

This needs to be completed by the person raising the PR.

  • I have selected the correct Assignee
  • I have linked the correct Issue

@netlify
Copy link
Copy Markdown

netlify bot commented Dec 18, 2025

Deploy Preview for ons-design-system-preview ready!

Name Link
🔨 Latest commit 4d216e5
🔍 Latest deploy log https://app.netlify.com/projects/ons-design-system-preview/deploys/6965470f4f6de40008222409
😎 Deploy Preview https://deploy-preview-3770--ons-design-system-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@SriHV SriHV self-assigned this Dec 18, 2025
@SriHV SriHV added the Dependencies Pull requests that update a dependency file label Dec 18, 2025
@SriHV SriHV marked this pull request as ready for review December 18, 2025 18:01
@SriHV SriHV requested a review from a team as a code owner December 18, 2025 18:01
This was referenced Jan 7, 2026
@SriHV SriHV merged commit daed76c into main Jan 13, 2026
14 checks passed
@SriHV SriHV deleted the fix-js-yaml-security-vulnerability branch January 13, 2026 11:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants