chore(deps): update dependency js-yaml@3 to v4 [security] - #2027
renovate[bot] wants to merge 1 commit into
Conversation
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit baff502. Configure here.
| brace-expansion@2: "^2.1.2" | ||
| brace-expansion@5: "^5.0.7" | ||
| js-yaml@3: "^3.15.1" | ||
| js-yaml@3: "^4.3.2" |
There was a problem hiding this comment.
js-yaml v4 override breaks consumers
High Severity
The js-yaml@3 override now resolves to ^4.3.2. That major jump removes safeLoad, which read-yaml-file, front-matter, and @yarnpkg/parsers still call. Changesets and Nx then throw when they parse YAML.
Reviewed by Cursor Bugbot for commit baff502. Configure here.


This PR contains the following updates:
^3.15.1→^4.3.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
CVE-2026-84375 / GHSA-2883-xcg3-v3hh
More information
Details
Summary
maxTotalMergeKeysdoes not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.Example
For every target, the loader iterates all
Nelements ofarr. This results inO(N * K)work whiletotalMergeKeysremains unchanged.PoC
Observed results:
Impact
An attacker can submit a relatively small YAML document that causes prolonged CPU consumption despite the default
maxTotalMergeKeyslimit.Fix
Count each merge-source mapping as one budget unit, in addition to counting its keys.
Difference with v5
In v3 & v4, merge is enabled by default. So, the severity score is higher.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodeca/js-yaml (js-yaml@3)
v4.3.2Compare Source
v4.3.1Compare Source
v4.3.0Compare Source
v4.2.0Compare Source
Added
docs/safety.mdwith notes about processing untrusted YAML.maxDepth(100) loader option. Not a problem, but gives a betterexception instead of RangeError on stack overflow.
maxMergeSeqLength(20) loader option. Not a problem aftermergefix,but an additional restriction for safety.
dist/builds.Changed
dist/files are no longer kept in the repository.Fixed
Security
elements (makes sense for malformed files > 10K).
v4.1.1Compare Source
Security
v4.1.0Compare Source
Added
yaml.types.XXX.optionsproperty with original arguments kept as they were(see
yaml.types.int.optionsas an example).Changed
Schema.extend()now keeps old type order in case of conflicts(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as
abcdinstead ofcbad).v4.0.0Compare Source
Changed
!!js/function,!!js/regexp,!!js/undefinedaremoved to js-yaml-js-types package.
safe*functions. Useload,loadAll,dumpinstead which are all now safe by default.
yaml.DEFAULT_SAFE_SCHEMAandyaml.DEFAULT_FULL_SCHEMAare removed, useyaml.DEFAULT_SCHEMAinstead.yaml.Schema.create(schema, tags)is removed, useschema.extend(tags)instead.!!binarynow always mapped toUint8Arrayon load./libfolder.01234is now decimal,0o1234is octal,1:23is parsed as string instead of base60).dump()no longer quotes:,[,],(,)except when necessary, #470, #557.(X:Y)instead ofat line X, column Y(also present in compact format), #332.dump()now serializesundefinedasnullin collections and removes keys withundefinedin mappings, #571.dump()withskipInvalid=truenow serializes invalid items in collections as null.!are now dumped as!taginstead of!<!tag>, #576.tag:yaml.org,2002:are now shorthanded using!!, #258.Added
.mjs(es modules) support.quotingTypeandforceQuotesoptions for dumper to configurestring literal style, #290, #529.
styles: { '!!null': 'empty' }option for dumper(serializes
{ foo: null }as "foo:"), #570.replaceroption (similar to option in JSON.stringify), #339.Tagcan now handle all tags or multiple tags with the same prefix, #385.Fixed
dump(), #587.[foo,,bar]) now throw an exceptioninstead of producing null, #321.
__proto__key no longer overrides object prototype, #164.bower.json.load()and url-encoded indump()(previously usage of custom non-ascii tags may have led to invalid YAML that can't be parsed).
v3.15.2Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.