Skip to content

Bump yaml from 2.8.2 to 2.8.3 - #87

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/yaml-2.8.3
Open

Bump yaml from 2.8.2 to 2.8.3#87
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/yaml-2.8.3

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 23, 2026

Copy link
Copy Markdown
Contributor

Bumps yaml from 2.8.2 to 2.8.3.

Release notes

Sourced from yaml's releases.

v2.8.3

  • Add trailingComma ToString option for multiline flow formatting (#670)
  • Catch stack overflow during node composition (1e84ebb)
Commits
  • ce14587 2.8.3
  • 1e84ebb fix: Catch stack overflow during node composition
  • 6b24090 ci: Include Prettier check in lint action
  • 9424dee chore: Refresh lockfile
  • d1aca82 Add trailingComma ToString option for multiline flow formatting (#670)
  • 4321509 ci: Drop the branch filter from GitHub PR actions
  • 47207d0 chore: Update docs-slate
  • 5212fae chore: Update docs-slate
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.2 to 2.8.3.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.2...v2.8.3)
---
updated-dependencies:
- dependency-name: yaml
dependency-version: 2.8.3
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 23, 2026
@dependabot
dependabotBot requested a review from ncalteen as a code ownerMay 23, 2026 00:06
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 23, 2026
@github-actions

Copy link
Copy Markdown

MegaLinter analysis: Error

DescriptorLinterFilesFixedErrorsWarningsElapsed time
✅ ACTIONactionlint5000.06s
❌ ACTIONzizmor5101.22s
✅ JSONjsonlint23000.14s
✅ JSONnpm-package-json-lintyesnono0.96s
✅ JSONprettier23001.42s
✅ JSONv8r230013.16s
✅ MARKDOWNmarkdownlint1000.8s
✅ REPOSITORYcheckovyesnono19.57s
✅ REPOSITORYgitleaksyesnono0.47s
✅ REPOSITORYgit_diffyesnono0.01s
✅ REPOSITORYgrypeyesnono54.78s
❌ REPOSITORYosv-scanneryes22no2.51s
✅ REPOSITORYsecretlintyesnono1.09s
✅ REPOSITORYsyftyesnono2.64s
✅ REPOSITORYtrivy-sbomyesnono0.82s
✅ REPOSITORYtrufflehogyesnono12.89s
✅ TYPESCRIPTeslint8006.06s
✅ TYPESCRIPTprettier8001.14s
✅ YAMLprettier19000.93s
✅ YAMLv8r19009.63s
✅ YAMLyamllint19000.6s

Detailed Issues

❌ REPOSITORY / osv-scanner - 22 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned package-lock.json file and found 527 packages
End status: 46 dirs visited, 168 inodes visited, 1 Extract calls, 21.324554ms elapsed, 21.324784ms wall time
Total 9 packages affected by 22 known vulnerabilities (1 Critical, 11 High, 9 Medium, 1 Low, 0 Unknown) from 1 ecosystem.
22 vulnerabilities can be fixed.
+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
| https://osv.dev/GHSA-f886-m6hf-6m8v | 6.5 | npm | brace-expansion (dev) | 1.1.12 | 1.1.13 | package-lock.json |
| https://osv.dev/GHSA-f886-m6hf-6m8v | 6.5 | npm | brace-expansion (dev) | 2.0.2 | 2.0.3 | package-lock.json |
| https://osv.dev/GHSA-f886-m6hf-6m8v | 6.5 | npm | brace-expansion (dev) | 5.0.4 | 5.0.5 | package-lock.json |
| https://osv.dev/GHSA-jxxr-4gwj-5jf2 | 6.5 | npm | brace-expansion (dev) | 5.0.4 | 5.0.6 | package-lock.json |
| https://osv.dev/GHSA-2qvq-rjwj-gvw9 | 4.7 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-2w6w-674q-4c4q | 9.8 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-3mfm-83xf-c92r | 8.1 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-442j-39wm-28r2 | 3.7 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-7rx3-28cr-v5wh | 4.8 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-9cx6-37pm-9jff | 7.5 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-xhpv-hc6g-r9c6 | 8.1 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-xjpj-3mr7-gcpf | 8.2 | npm | handlebars (dev) | 4.7.8 | 4.7.9 | package-lock.json |
| https://osv.dev/GHSA-f23m-r3pf-42rh | 6.5 | npm | lodash (dev) | 4.17.23 | 4.18.0 | package-lock.json |
| https://osv.dev/GHSA-r5fr-rjxr-66jc | 8.1 | npm | lodash (dev) | 4.17.23 | 4.18.0 | package-lock.json |
| https://osv.dev/GHSA-23c5-xmqv-rm74 | 7.5 | npm | minimatch (dev) | 9.0.3 | 9.0.7 | package-lock.json |
| https://osv.dev/GHSA-3ppc-4f35-3m26 | 8.7 | npm | minimatch (dev) | 9.0.3 | 9.0.6 | package-lock.json |
| https://osv.dev/GHSA-7r86-cg39-jmmj | 7.5 | npm | minimatch (dev) | 9.0.3 | 9.0.7 | package-lock.json |
| https://osv.dev/GHSA-3v7f-55p6-f55p | 5.3 | npm | picomatch (dev) | 2.3.1 | 2.3.2 | package-lock.json |
| https://osv.dev/GHSA-c2c7-rcm5-vvqj | 7.5 | npm | picomatch (dev) | 2.3.1 | 2.3.2 | package-lock.json |
| https://osv.dev/GHSA-3v7f-55p6-f55p | 5.3 | npm | picomatch (dev) | 4.0.3 | 4.0.4 | package-lock.json |
| https://osv.dev/GHSA-c2c7-rcm5-vvqj | 7.5 | npm | picomatch (dev) | 4.0.3 | 4.0.4 | package-lock.json |
| https://osv.dev/GHSA-w5hq-g745-h8pq | 7.5 | npm | uuid (dev) | 8.3.2 | 11.1.1 | package-lock.json |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+-------------------+
❌ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'ref-confusion' audit failed on file://.github/workflows/check-dist.yml
Caused by:
0: error in 'ref-confusion' audit
1: couldn't list branches for actions/checkout
2: request error while accessing GitHub API
3: HTTP status client error (401 Unauthorized) for url (https://github.com/actions/checkout.git/git-upload-pack)
[ZizmorLinter] Zizmor failed to reach the GitHub API.
To allow zizmor to use GITHUB_TOKEN, add the following to your .mega-linter.yml:
ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
- GITHUB_TOKEN

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.5.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,TYPESCRIPT_ES,TYPESCRIPT_PRETTIER,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants