chore(deps-dev): bump astro from 4.16.19 to 7.3.5 - #24955
dependabot[bot] wants to merge 1 commit into
Conversation
| @@ -18236,18 +18296,18 @@ js-tokens@^10.0.0: | |||
| resolved "https://registry.yarnpkg.com/js-tokens/-/js-tokens-4.0.0.tgz#19203fb59991df98e3a287050d4647cdeaf32499" | |||
| integrity sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ== | |||
|
|
|||
| js-yaml@^3.13.0, js-yaml@^3.13.1: | |||
| js-yaml@^3.13.1: | |||
There was a problem hiding this comment.
High severity vulnerability may affect your project—review required:
Line 18299 lists a dependency (js-yaml) with a known High severity vulnerability.
ℹ️ Why this matters
Affected versions of js-yaml are vulnerable to Inefficient Algorithmic Complexity / Uncontrolled Resource Consumption. js-yaml is vulnerable to CPU exhaustion when parsing untrusted YAML: the maxTotalMergeKeys budget is only charged for keys that a merge (<<) source actually contributes, so empty mappings cost nothing against the limit. A small document that merges a long sequence of empty mappings repeatedly forces O(N*K) work while the counter stays flat, stalling the process. Merge keys are part of the default schema for every load entrypoint (load, loadAll, and the 3.x safeLoad/safeLoadAll), and lowering maxTotalMergeKeys does not mitigate it.
References: https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-69712, GHSA, CVE
To resolve this comment:
Check if you are using js-yaml on the CLI.
- If you're affected, upgrade this dependency to at least version 3.15.2 at yarn.lock.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
8139006 to
d66d375
Compare
Bumps [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) from 4.16.19 to 7.3.5. - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro) --- updated-dependencies: - dependency-name: astro dependency-version: 7.3.5 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
d66d375 to
e3846d2
Compare
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps astro from 4.16.19 to 7.3.5.
Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
c2e0164[ci] release (#18113)2b8b2e8feat: add render component (#17736)790c6f7[ci] release (#18035)9d17bf1Update dependency obug to v3 (#18100)43657c4Fix i18n domain host validation (#18096)00393ffUpdate dependency vitest [SECURITY] (#18026)40896acfix(incremental): resolve asset placeholders in modules or compiled CSS (#18063)0429805fix(errors): align three error names with their documented reference (#18074)3eab954[ci] format795a7e4Fix double-escaped ampersands in Markdown image alt and title attributes (#18...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for astro since your current version.