From 15312f535c4ef61aa9f05c2853589bc2c7c043f0 Mon Sep 17 00:00:00 2001 From: EugeniyKiyashko Date: Thu, 18 Jun 2026 01:42:19 +0400 Subject: [PATCH] Fix js-yaml vulnerability override --- pnpm-lock.yaml | 30 +++++------------------------- pnpm-workspace.yaml | 1 + 2 files changed, 6 insertions(+), 25 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index fd67c4929..29dbd8509 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -9,6 +9,7 @@ overrides: semver@>=2.0.0-alpha <5.7.2: '>=5.7.2' ip-address@<=10.1.0: '>=10.2.0' basic-ftp@<=5.3.0: '>=5.3.1' + js-yaml@<=4.1.1: ^4.2.0 importers: @@ -945,9 +946,6 @@ packages: resolution: {integrity: sha512-KMReFUr0B4t+D+OBkjR3KYqvocp2XaSzO55UcB6mgQMd3KbcE+mWTyvVV7D/zsdEbNnV6acZUutkiHQXvTr1Rw==} engines: {node: '>= 8'} - argparse@1.0.10: - resolution: {integrity: sha512-o5Roy6tNG4SL/FOkCAN6RzjiakZS25RLYFrcMttJqbdd8BWrnA+fGz57iN5Pb06pvBGvl5gQ0B48dJlslXvoTg==} - argparse@2.0.1: resolution: {integrity: sha512-8+9WqebbFzpX9OR+Wa6O29asIogeRMzcGtAINdpMHHyAg10f05aSFVBbcEqGf/PXw1EjAZ+q2/bEBg3DvurK3Q==} @@ -2313,10 +2311,6 @@ packages: js-tokens@4.0.0: resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==} - js-yaml@3.14.2: - resolution: {integrity: sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==} - hasBin: true - js-yaml@4.2.0: resolution: {integrity: sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==} hasBin: true @@ -2998,9 +2992,6 @@ packages: spawn-sync@1.0.15: resolution: {integrity: sha512-9DWBgrgYZzNghseho0JOuh+5fg9u6QWhAWa51QC7+U5rCheZ/j1DrEZnyE0RBBRqZ9uEXGPgSSM0nky6burpVw==} - sprintf-js@1.0.3: - resolution: {integrity: sha512-D9cPgkvLlV3t3IzL0D0YLvGA9Ahk4PcvVwUbN0dSGr1aP0Nrt4AEnTUbuGvquEC0mA64Gqt1fzirlRs5ibXx8g==} - ssim.js@3.5.0: resolution: {integrity: sha512-Aj6Jl2z6oDmgYFFbQqK7fght19bXdOxY7Tj03nF+03M9gCBAjeIiO8/PlEGMfKDwYpw4q6iBqVq2YuREorGg/g==} @@ -3644,7 +3635,7 @@ snapshots: globals: 13.24.0 ignore: 4.0.6 import-fresh: 3.3.1 - js-yaml: 3.14.2 + js-yaml: 4.2.0 minimatch: 3.1.5 strip-json-comments: 3.1.1 transitivePeerDependencies: @@ -3720,7 +3711,7 @@ snapshots: camelcase: 5.3.1 find-up: 4.1.0 get-package-type: 0.1.0 - js-yaml: 3.14.2 + js-yaml: 4.2.0 resolve-from: 5.0.0 '@istanbuljs/schema@0.1.6': {} @@ -4289,10 +4280,6 @@ snapshots: normalize-path: 3.0.0 picomatch: 2.3.2 - argparse@1.0.10: - dependencies: - sprintf-js: 1.0.3 - argparse@2.0.1: {} array-buffer-byte-length@1.0.2: @@ -5119,7 +5106,7 @@ snapshots: import-fresh: 3.3.1 imurmurhash: 0.1.4 is-glob: 4.0.3 - js-yaml: 3.14.2 + js-yaml: 4.2.0 json-stable-stringify-without-jsonify: 1.0.1 levn: 0.4.1 lodash.merge: 4.6.2 @@ -6096,11 +6083,6 @@ snapshots: js-tokens@4.0.0: {} - js-yaml@3.14.2: - dependencies: - argparse: 1.0.10 - esprima: 4.0.1 - js-yaml@4.2.0: dependencies: argparse: 2.0.1 @@ -6820,8 +6802,6 @@ snapshots: concat-stream: 1.6.2 os-shim: 0.1.3 - sprintf-js@1.0.3: {} - ssim.js@3.5.0: {} stack-utils@2.0.6: @@ -7023,7 +7003,7 @@ snapshots: commander: 2.20.3 diff: 4.0.4 glob: 7.2.3 - js-yaml: 3.14.2 + js-yaml: 4.2.0 minimatch: 3.1.5 mkdirp: 0.5.6 resolve: 1.22.12 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 561cc1362..920519e0d 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -12,3 +12,4 @@ overrides: semver@>=2.0.0-alpha <5.7.2: ">=5.7.2" ip-address@<=10.1.0: ">=10.2.0" basic-ftp@<=5.3.0: ">=5.3.1" + "js-yaml@<=4.1.1": "^4.2.0"