Skip to content

chore(deps): Bump yaml from 1.10.2 to 1.10.3 in /frontend#366

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/yaml-1.10.3
Closed

chore(deps): Bump yaml from 1.10.2 to 1.10.3 in /frontend#366
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/yaml-1.10.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 26, 2026

Copy link
Copy Markdown
Contributor

Bumps yaml from 1.10.2 to 1.10.3.

Commits
  • cfe8f04 1.10.3
  • 7abcf45 fix: Catch stack overflow during CST composition
  • a0252f8 chore: Add rules avoiding processing of tests/json-test-suite
  • a5e83b0 style: Apply updates Prettier rules
  • b8ddca0 chore: Refresh lockfile
  • 395f892 ci: Use a different (working) submodule checkout
  • 6fd2720 test-events: Add {} and [] indicators to flow maps & sequences
  • See full diff in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Update Analysis

Update Type: patch
Security Update: false
Risk Level: low
Auto-merge Eligible: true

Analysis Details

  • PR Title: chore(deps): Bump yaml from 1.10.2 to 1.10.3 in /frontend
  • Updated by: dependabot[bot]
  • Branch: dependabot/npm_and_yarn/frontend/yaml-1.10.3

Security Audit Results

Frontend (npm audit)

INFO - Unable to parse npm audit results

Backend (safety check)

INFO - Unable to parse safety check results

@github-actions

Copy link
Copy Markdown
Contributor

Manual Review Required

This dependency update requires manual review:

Reason:

  • Update Type: patch
  • Risk Level: low
  • Auto-merge Eligible: true

Review Checklist:

  • Review changelog for breaking changes
  • Test critical application paths
  • Verify security implications
  • Check for API compatibility
  • Validate configuration changes

Next Steps:

  1. Review the changes thoroughly
  2. Test locally if needed
  3. Approve and merge when ready

cc: @maintainers

Bumps [yaml](https://github.com/eemeli/yaml) from 1.10.2 to 1.10.3.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v1.10.2...v1.10.3)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 1.10.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/yaml-1.10.3 branch from 848c0b2 to 6819ca4 Compare April 14, 2026 01:35
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Update Analysis

Update Type: patch
Security Update: false
Risk Level: low
Auto-merge Eligible: true

Analysis Details

  • PR Title: chore(deps): Bump yaml from 1.10.2 to 1.10.3 in /frontend
  • Updated by: dependabot[bot]
  • Branch: dependabot/npm_and_yarn/frontend/yaml-1.10.3

Security Audit Results

Frontend (npm audit)

INFO - Unable to parse npm audit results

Backend (safety check)

INFO - Unable to parse safety check results

@github-actions

Copy link
Copy Markdown
Contributor

Manual Review Required

This dependency update requires manual review:

Reason:

  • Update Type: patch
  • Risk Level: low
  • Auto-merge Eligible: true

Review Checklist:

  • Review changelog for breaking changes
  • Test critical application paths
  • Verify security implications
  • Check for API compatibility
  • Validate configuration changes

Next Steps:

  1. Review the changes thoroughly
  2. Test locally if needed
  3. Approve and merge when ready

cc: @maintainers

@remyluslosius

Copy link
Copy Markdown
Contributor

Closing as Dependabot queue cleanup: this individual PR predates the grouped Dependabot config and is months behind main. Dependabot will re-propose any still-outstanding update for this package at its current version in the next grouped run (see #489 production / #488 development). Closing avoids the stale-version + package-lock conflict cascade.

@dependabot @github

dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/frontend/yaml-1.10.3 branch June 11, 2026 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code manual-review-required risk-low update-patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant