Skip to content

chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript - #3623

Merged
liamcrumm merged 1 commit into
mainfrom
dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3
Aug 12, 2026
Merged

liamcrumm merged 1 commit into
mainfrom
dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 5.2.2 to 5.2.3.

Changelog

Sourced from js-yaml's changelog.

[5.2.3] - 2026-08-01

Fixed

  • Prevent prototype fallback when resolving tags and mapping entries, #782.
  • Resolve !!timestamp years 0000-0099 correctly, #775.
  • Preserve implicit null mapping values before document markers and reject unpaired mapping event streams, #784.
  • Preserve folded scalar values with tab-indented lines when round-tripping a parsed AST through present(); dump() and loading are unaffected, #780.
Commits
  • 6740445 5.2.3 released
  • 94e766d Update changelog
  • c3bd7ca Polish previous commit, #780
  • 00209b6 presenter: treat a tab-indented line in a folded scalar as more-indented (#780)
  • 40fcb4f Fix missing mapping values before document markers and reject unpaired mappin...
  • 49280f3 Fix !!timestamp resolution for years 0000-0099, #775
  • 355dc96 fix: prevent prototype fallback in tag and harden object lookups, #782 (than...
  • d524f83 docs: add contributing guidelines
  • See full diff in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 5, 2026
Copilot AI lite review requested due to automatic review settings August 5, 2026 08:32
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 5, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/js-yaml 5.2.3 🟢 6.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1030 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 3/30 approved changesets -- score normalized to 1
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 4security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • agent-governance-typescript/package-lock.json

@github-actions github-actions Bot removed the dependencies Pull requests that update a dependency file label Aug 5, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates the js-yaml dependency version in the TypeScript agent governance package.

Changes:

  • Bumped js-yaml from 5.2.2 to 5.2.3.
Files not reviewed (1)
  • agent-governance-typescript/package-lock.json: Generated file

@github-actions github-actions Bot added the size/S Small PR (< 50 lines) label Aug 5, 2026
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3.

Summary: ➕ 0 added · ➖ 0 removed · 🔄 1 bumped

🔄 Bumped

npm (1)

Package From To
js-yaml 5.2.2 5.2.3

@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(deps): Bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript Aug 5, 2026
@prayagupa

Copy link
Copy Markdown
Collaborator

Dependabot (@dependabot) rebase

The Validate PR title red is stale (the title is already lowercase); a rebase re-runs it. The 7-day cooling-off will keep gating the merge until js-yaml 5.2.3 has aged past 7 days.

Copilot AI review requested due to automatic review settings August 5, 2026 17:53
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3 branch from c2e8e32 to 54d18c8 Compare August 5, 2026 17:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

Files not reviewed (1)
  • agent-governance-typescript/package-lock.json: Generated file

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Dependabot (@dependabot) rebase

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 5.2.2 to 5.2.3.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.2.2...5.2.3)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript chore(deps): Bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript Aug 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3 branch from 54d18c8 to 31bdffe Compare August 7, 2026 20:40
@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(deps): Bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript chore(deps): bump js-yaml from 5.2.2 to 5.2.3 in /agent-governance-typescript Aug 7, 2026
@liamcrumm
liamcrumm merged commit 7c488aa into main Aug 12, 2026
103 of 106 checks passed
@liamcrumm
liamcrumm deleted the dependabot/npm_and_yarn/agent-governance-typescript/js-yaml-5.2.3 branch August 12, 2026 18:07
Imran Siddique (imran-siddique) added a commit that referenced this pull request Aug 12, 2026
#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
MohammadHaroonAbuomar pushed a commit that referenced this pull request Sep 15, 2026
…ages, with audit (#3721)

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* docs(deps): audit the sdk 5.0.0 bump in the three CLI packages

The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag

The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): note that the SDK js-yaml repin already landed on main

#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct the js-yaml audit, and restore the lockfile overrides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with #3843, #3844 and #3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: #3843, #3844 and
#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only #3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): reconcile remaining js-yaml audit claims

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct SDK source js-yaml pin history

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ages, with audit (microsoft#3721)

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* docs(deps): audit the sdk 5.0.0 bump in the three CLI packages

The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag

The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): note that the SDK js-yaml repin already landed on main

microsoft#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct the js-yaml audit, and restore the lockfile overrides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with microsoft#3843, microsoft#3844 and microsoft#3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: microsoft#3843, microsoft#3844 and
microsoft#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only microsoft#3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): reconcile remaining js-yaml audit claims

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct SDK source js-yaml pin history

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/S Small PR (< 50 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants