Repository navigation
chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript - #3623
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the js-yaml dependency version in the TypeScript agent governance package.
Changes:
- Bumped
js-yamlfrom5.2.2to5.2.3.
Files not reviewed (1)
- agent-governance-typescript/package-lock.json: Generated file
📦 Dependency diff (SBOM)Comparing main → dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3. Summary: ➕ 0 added · ➖ 0 removed · 🔄 1 bumped 🔄 Bumped
|
| Package | From | To |
|---|---|---|
| js-yaml | 5.2.2 | 5.2.3 |
|
Dependabot (@dependabot) rebase The |
c2e8e32 to
54d18c8
Compare
|
Dependabot (@dependabot) rebase |
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.2 to 5.2.3. - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@5.2.2...5.2.3) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 5.2.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
54d18c8 to
31bdffe
Compare
#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the recommendation to repin was already stale when written. The residual exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is immutable, so it closes on the next SDK publish rather than by any change to these lockfiles. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
…ages, with audit (#3721) * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * docs(deps): audit the sdk 5.0.0 bump in the three CLI packages The vendored-patch-audit gate greps the PR's own diff for the audit doc, and exempts dependabot only for non-major updates, so a semver-major bump opened by dependabot can never satisfy it on its own branch. Carries the three dependabot commits unchanged and adds the audit alongside them. Records that the bump does not clear these packages of a js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in 5.2.1, which is first patched in 5.2.2. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag The audit doc above failed spell-check on fragments of GHSA identifiers (xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one to the dictionary would grow it by three entries per advisory cited and would recur on every future security audit doc. Matching the identifier shape instead fixes the class. Also adds omap, the YAML ordered-map tag, which is a real term rather than a random one. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): note that the SDK js-yaml repin already landed on main #3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the recommendation to repin was already stale when written. The residual exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is immutable, so it closes on the next SDK publish rather than by any change to these lockfiles. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct the js-yaml audit, and restore the lockfile overrides The audit read the SDK's declared js-yaml and concluded the bump exchanged two HIGH advisories for one. It does not. All three packages declare overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves node_modules/js-yaml to 4.2.0 both before and after the SDK bump. npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never installed. Also restores the root "overrides" block in the three lockfiles. package.json declares it and main's lockfiles record it; the regenerated lockfiles here dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded the reason for its own pin. npm ci succeeds either way, which is why nothing caught it. Names the conflict with #3843, #3844 and #3875, which move the override to 4.3.1 in the same files and do clear both advisories. Reported by @prayagupa in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7 Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it The js-yaml section said `npm audit` reports "both, and no others". A third HIGH was published on 2026-09-08 and is also in range for the 4.2.0 the override holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2. It postdates the npm audit output the document quotes, which is now said explicitly rather than leaving the quoted output looking incomplete. It also changes which fix is sufficient, so that is recorded: #3843, #3844 and #3875 each raise the override to 4.3.1, which clears the first two advisories and leaves this one in range. Only #3894, at 4.3.2, clears all three. Verified against the advisory API, with a control advisory resolved through the same lookup, and the four PRs' own diffs read for the version each moves to. Raised by @MohammadHaroonAbuomar in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): reconcile remaining js-yaml audit claims Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct SDK source js-yaml pin history Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ages, with audit (microsoft#3721) * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * docs(deps): audit the sdk 5.0.0 bump in the three CLI packages The vendored-patch-audit gate greps the PR's own diff for the audit doc, and exempts dependabot only for non-major updates, so a semver-major bump opened by dependabot can never satisfy it on its own branch. Carries the three dependabot commits unchanged and adds the audit alongside them. Records that the bump does not clear these packages of a js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in 5.2.1, which is first patched in 5.2.2. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag The audit doc above failed spell-check on fragments of GHSA identifiers (xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one to the dictionary would grow it by three entries per advisory cited and would recur on every future security audit doc. Matching the identifier shape instead fixes the class. Also adds omap, the YAML ordered-map tag, which is a real term rather than a random one. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): note that the SDK js-yaml repin already landed on main microsoft#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the recommendation to repin was already stale when written. The residual exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is immutable, so it closes on the next SDK publish rather than by any change to these lockfiles. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct the js-yaml audit, and restore the lockfile overrides The audit read the SDK's declared js-yaml and concluded the bump exchanged two HIGH advisories for one. It does not. All three packages declare overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves node_modules/js-yaml to 4.2.0 both before and after the SDK bump. npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never installed. Also restores the root "overrides" block in the three lockfiles. package.json declares it and main's lockfiles record it; the regenerated lockfiles here dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded the reason for its own pin. npm ci succeeds either way, which is why nothing caught it. Names the conflict with microsoft#3843, microsoft#3844 and microsoft#3875, which move the override to 4.3.1 in the same files and do clear both advisories. Reported by @prayagupa in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7 Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it The js-yaml section said `npm audit` reports "both, and no others". A third HIGH was published on 2026-09-08 and is also in range for the 4.2.0 the override holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2. It postdates the npm audit output the document quotes, which is now said explicitly rather than leaving the quoted output looking incomplete. It also changes which fix is sufficient, so that is recorded: microsoft#3843, microsoft#3844 and microsoft#3875 each raise the override to 4.3.1, which clears the first two advisories and leaves this one in range. Only microsoft#3894, at 4.3.2, clears all three. Verified against the advisory API, with a control advisory resolved through the same lookup, and the four PRs' own diffs read for the version each moves to. Raised by @MohammadHaroonAbuomar in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): reconcile remaining js-yaml audit claims Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct SDK source js-yaml pin history Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Bumps js-yaml from 5.2.2 to 5.2.3.
Changelog
Sourced from js-yaml's changelog.
Commits
67404455.2.3 released94e766dUpdate changelogc3bd7caPolish previous commit, #78000209b6presenter: treat a tab-indented line in a folded scalar as more-indented (#780)40fcb4fFix missing mapping values before document markers and reject unpaired mappin...49280f3Fix !!timestamp resolution for years 0000-0099, #775355dc96fix: prevent prototype fallback in tag and harden object lookups, #782 (than...d524f83docs: add contributing guidelines