Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 14, 2025

This PR contains the following updates:

Package Change Age Confidence
js-yaml 4.1.04.1.1 age confidence

GitHub Vulnerability Alerts

CVE-2025-64718

Impact

In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted.

Patches

Problem is patched in js-yaml 4.1.1 and 3.14.2.

Workarounds

You can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).

References

https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html


Release Notes

nodeca/js-yaml (js-yaml)

v4.1.1

Compare Source

Security
  • Fix prototype pollution issue in yaml merge (<<) operator.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) November 14, 2025 16:02
@codecov
Copy link

codecov bot commented Nov 14, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.65%. Comparing base (d4bc95d) to head (a2145ba).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #1437   +/-   ##
=======================================
  Coverage   90.65%   90.65%           
=======================================
  Files         421      421           
  Lines        9519     9519           
  Branches     2215     2287   +72     
=======================================
  Hits         8629     8629           
+ Misses        856      853    -3     
- Partials       34       37    +3     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from b49ccb3 to a564733 Compare November 17, 2025 00:11
@renovate renovate bot changed the title chore(deps): update dependency js-yaml to v4.1.1 [security] chore(deps): update dependency js-yaml to v4.1.1 [security] - autoclosed Nov 19, 2025
@renovate renovate bot closed this Nov 19, 2025
auto-merge was automatically disabled November 19, 2025 00:56

Pull request was closed

@renovate renovate bot deleted the renovate/npm-js-yaml-vulnerability branch November 19, 2025 00:56
@renovate renovate bot changed the title chore(deps): update dependency js-yaml to v4.1.1 [security] - autoclosed chore(deps): update dependency js-yaml to v4.1.1 [security] Nov 21, 2025
@renovate renovate bot reopened this Nov 21, 2025
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 2 times, most recently from a564733 to 1ea545b Compare November 21, 2025 12:19
@renovate renovate bot enabled auto-merge (squash) November 21, 2025 18:49
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 1ea545b to b737982 Compare November 24, 2025 00:11
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 3 times, most recently from 38d59f7 to b49ab66 Compare December 8, 2025 00:11
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 2 times, most recently from bc6bb06 to 182bbf3 Compare December 15, 2025 00:11
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 182bbf3 to 50d8b92 Compare December 22, 2025 00:11
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 6 times, most recently from 94f9090 to 220487f Compare January 12, 2026 00:11
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 3 times, most recently from 09f3c3f to 4c737ff Compare January 19, 2026 00:12
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch 2 times, most recently from 13afc43 to 32c866c Compare January 21, 2026 10:25
@renovate renovate bot force-pushed the renovate/npm-js-yaml-vulnerability branch from 32c866c to a2145ba Compare January 26, 2026 00:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants