Skip to content

fix: update Antigravity js-yaml override - #3843

Closed
Jeff Stock (jstock03) wants to merge 3 commits into
microsoft:mainfrom
jstock03:fix/antigravity-js-yaml-advisories
Closed

Jeff Stock (jstock03) wants to merge 3 commits into
microsoft:mainfrom
jstock03:fix/antigravity-js-yaml-advisories

Conversation

@jstock03

Copy link
Copy Markdown
Contributor

Why

S360 and Component Governance flag the Antigravity CLI's overridden js-yaml 4.2.0 for two related advisories. Both alerts apply to the same installed package instance, so one override and lockfile update is the smallest complete remediation.

Vulnerabilities

Change

Update only the Antigravity package's transitive js-yaml override and lockfile from 4.2.0 to 4.3.1.

Validation

  • npm ci reports zero vulnerabilities
  • npm ls js-yaml resolves js-yaml 4.3.1 overridden
  • npm run check
  • npm test passes 22 tests

Signed-off-by: Jeff Stock <jstock@microsoft.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the size/S Small PR (< 50 lines) label Aug 27, 2026
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Signed-off-by: Jeff Stock <jstock@microsoft.com>
@github-actions github-actions Bot added documentation Improvements or additions to documentation size/M Medium PR (< 200 lines) and removed size/S Small PR (< 50 lines) labels Aug 27, 2026
Signed-off-by: Jeff Stock <jstock@microsoft.com>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The bump itself is right and I verified the advisory chain rather than taking the audit doc's word
for it. There is one problem in the lockfile that I would fix before this merges, and it is the same
in all three of your js-yaml PRs (#3843, #3844, #3875).

The bump is warranted and 4.3.1 is the correct target.

advisory severity affected first patched
GHSA-52cp-r559-cp3m (CVE-2026-59869) high >=4.0.0 <4.3.0 4.3.0
GHSA-5p4m-2wfm-xmqj high >=4.0.0 <4.3.1 4.3.1

So 4.2.0 is exposed to both and 4.3.1 clears both. I also checked that 4.3.1 is not itself carrying
an open advisory: the only newer high against js-yaml is GHSA-pm4m-ph32-ghv5 (CVE-2026-73643), which
is scoped to >=5.0.0 <=5.2.1 and does not reach the 4.x line. The audit doc is accurate.

The lockfile problem. The new js-yaml entry reads:

"resolved": "https://ms-feed-12.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/js-yaml/-/js-yaml-4.3.1.tgz",
"integrity": "sha1-ASFsAB1n9I4s1WDXCMevIQkKOEg="

Two things went wrong there, both artifacts of npm install having run against an internal Azure
DevOps mirror rather than the public registry.

The resolved URL points at an internal feed. #3844 has ms-feed-2 and this one and #3875 have
ms-feed-12, which is a good tell that it is whichever mirror node the machine happened to hit. An
external contributor or a fork's CI running npm ci against that URL does not get the same
guarantees, and the URL is not stable.

More importantly, the integrity hash is SHA-1, where every other entry in every lockfile in this
repository is SHA-512. The public registry publishes:

"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz",
"integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ=="

The ADO feed returns the legacy dist.shasum instead, and npm records whatever it is given.

To be clear about what this is and is not: the artifact is genuine. I base64-decoded
ASFsAB1n9I4s1WDXCMevIQkKOEg= to 01216c001d67f48e2cd560d708c7af21090a3848, which is exactly the
shasum npm publishes for js-yaml 4.3.1, so you fetched the right tarball. The problem is the
integrity record: a SHA-1 pin is a materially weaker supply-chain guarantee than SHA-512, and this
is a security PR whose whole purpose is supply-chain hygiene.

I checked the blast radius. Across all 12 package-lock.json files on main there are currently
zero pkgs.visualstudio.com URLs and zero sha1- integrity entries. These three PRs would introduce
the first of both.

The fix is to regenerate the lockfile against the public registry, for example
npm install --registry=https://registry.npmjs.org with any .npmrc feed override out of the way,
and confirm the resulting entry carries the sha512- value above.

Non-blocking notes.

The lockfile also drops the "overrides": { "js-yaml": "4.2.0" } block from the root packages[""]
entry without replacing it with the 4.3.1 value, while package.json keeps the override. Worth
checking that comes back on regeneration, since a lockfile that does not record the override is a
lockfile that will not reproduce it.

Realigning the stale 4.0.0 package metadata to 5.0.0 is a genuine drive-by improvement and I am
glad it is called out explicitly in the audit doc rather than left as an unexplained diff line.

Everything else here is good. The audit doc is the right level of detail and it is the format the
Dependency Audit Trail gate wants.

Imran Siddique (imran-siddique) pushed a commit that referenced this pull request Sep 3, 2026
…ides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with #3843, #3844 and #3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Imran Siddique (imran-siddique) added a commit that referenced this pull request Sep 3, 2026
…ides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with #3843, #3844 and #3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • package-lock.json — the js-yaml 'resolved' URL points at ms-feed-12.pkgs.visualstudio.com (an internal feed); no lockfile on main uses that host, and an external 'npm ci' would fail to fetch it. Please regenerate against registry.npmjs.org.
  • 4.3.1 is still vulnerable: GHSA-2883-xcg3-v3hh (high, published 2026-09-08) is fixed in js-yaml 4.3.2, which is also the v4-legacy dist-tag and past the 7-day cooling window. #3894 already raises all four CLI packages to 4.3.2 with npmjs.org URLs — consider closing this in favor of #3894 rather than iterating.

Imran Siddique (imran-siddique) added a commit that referenced this pull request Sep 14, 2026
…ars it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: #3843, #3844 and
#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only #3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
MohammadHaroonAbuomar pushed a commit that referenced this pull request Sep 15, 2026
…ages, with audit (#3721)

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* docs(deps): audit the sdk 5.0.0 bump in the three CLI packages

The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag

The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): note that the SDK js-yaml repin already landed on main

#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct the js-yaml audit, and restore the lockfile overrides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with #3843, #3844 and #3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: #3843, #3844 and
#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only #3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): reconcile remaining js-yaml audit claims

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct SDK source js-yaml pin history

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Closing as stale: changes were requested on 2026-09-10 and there has been no response from the author for 16 days. The review notes above still apply; reopen this PR or open a fresh one when you can pick it up again.

Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ages, with audit (microsoft#3721)

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* docs(deps): audit the sdk 5.0.0 bump in the three CLI packages

The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag

The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): note that the SDK js-yaml repin already landed on main

microsoft#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct the js-yaml audit, and restore the lockfile overrides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with microsoft#3843, microsoft#3844 and microsoft#3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: microsoft#3843, microsoft#3844 and
microsoft#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only microsoft#3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): reconcile remaining js-yaml audit claims

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct SDK source js-yaml pin history

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants