Skip to content

fix: Update js-yaml v4.3.0 -> v4.3.1 to resolve high security issue - #6144

Closed
OIRNOIR wants to merge 1 commit into
Unitech:developmentfrom
OIRNOIR:patch-1
Closed

fix: Update js-yaml v4.3.0 -> v4.3.1 to resolve high security issue#6144
OIRNOIR wants to merge 1 commit into
Unitech:developmentfrom
OIRNOIR:patch-1

Conversation

@OIRNOIR

@OIRNOIR OIRNOIR commented Aug 11, 2026

Copy link
Copy Markdown
Q A
Bug fix? yes
New feature? no
BC breaks? no
Deprecations? no
Tests pass? yes
Fixed tickets None
License MIT
Doc PR N/A

npm audit shows a high severity vulnerability in js-yaml v4.3.0. A new version v4.3.1 was released last week to fix this vulnerability. The fixing commit can be viewed here: nodeca/js-yaml@c3cc4b0

@CLAassistant

CLAassistant commented Aug 11, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@Unitech

Unitech commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Thanks for the report.
This has been fixed on pm2@7.0.4

$ npm install pm2@7.0.4 -g
$ pm2 update

@Unitech Unitech closed this Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants