Skip to content

chore(deps): bump yaml from 2.8.4 to 2.9.0 - #360

Merged
Sun-sunshine06 merged 7 commits into
mainfrom
dependabot/npm_and_yarn/yaml-2.9.0
Sep 23, 2026
Merged

Sun-sunshine06 merged 7 commits into
mainfrom
dependabot/npm_and_yarn/yaml-2.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps yaml from 2.8.4 to 2.9.0.

Release notes

Sourced from yaml's releases.

v2.9.0

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack
Commits
  • ddb21b0 2.9.0
  • 167365b docs: Clarify that not all errors can be avoided
  • 6eca2a7 fix: Avoid calling Array.prototype.push.apply() with large source array
  • 0543cd5 fix(lexer): Avoid recursive calls that may exhaust the call stack
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.4 to 2.9.0.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.4...v2.9.0)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area:build Turbo/Vite/Biome/tsconfig toolchain chore Routine maintenance / non-feature work labels May 24, 2026
dependabot Bot and others added 3 commits June 16, 2026 07:40

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

No issues found. This is a correctly-scoped, single-dependency bump that only touches packages/shared/package.json and pnpm-lock.yaml.

  • packages/shared/package.json:20 — bumps yaml 2.8.4 → 2.9.0, preserving the exact-pin convention already used for this dependency. No new dependency is introduced, so the ≤ 30 prod-dependency budget is unaffected; yaml was already a shipped dependency (permissive/ISC), so the MIT-compatible shipped-dependency constraint does not change.
  • pnpm-lock.yaml — the packages/shared importer, the new yaml@2.9.0 packages:/snapshots: entries, and the yaml peer suffixes for vite/vitest/vitepress are all updated consistently to 2.9.0. The two upstream 2.9.0 fixes (Array.prototype.push.apply() with large source arrays, lexer call-stack recursion) are non-breaking per the release notes.
  • No application source files changed, so no new Vitest/Playwright coverage is warranted for this diff.

Questions

  • pnpm-lock.yaml retains the yaml@2.8.4 entry in both the packages: and snapshots: sections even though the visible reference sites (the packages/shared importer plus every vite/vitest/vitepress peer suffix) move to 2.9.0. Is yaml@2.8.4 still resolved transitively, or should those entries be pruned by a fresh pnpm install?

Summary

Review mode: initial

Routine Dependabot bump of yaml 2.8.4 → 2.9.0, limited to packages/shared/package.json and pnpm-lock.yaml. No code paths changed, no new dependency added, permissive license preserved, and the version is pinned consistently with the prior entry. No Blocker/Major/Minor findings.

Residual observation: the lockfile keeps a yaml@2.8.4 entry alongside the newly added yaml@2.9.0. This is harmless if yaml@2.8.4 is still pulled in transitively; if it is not, a re-run of pnpm install would prune it. pnpm lint && pnpm typecheck && pnpm test on CI should confirm nothing regressed.

Testing

Not run (automation). Existing CI (pnpm lint, pnpm typecheck, pnpm test) covers this change; a dependency bump alone does not require new tests.

Open-CoDesign Bot

@github-actions github-actions Bot added the area:desktop apps/desktop (Electron shell, renderer) label Sep 23, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • [Minor] Title/body vs. diff scope mismatch — the PR is described as yaml 2.8.4 → 2.9.0 only, but the diff also raises the desktop app's vite devDependency from ^7.3.2 to ^7.3.5 (apps/desktop/package.json:64), which pulls rollup@4.60.2 → 4.62.0, postcss@8.5.15, and tinyglobby@0.2.17 into that resolution (pnpm-lock.yaml). Nothing in the yaml bump requires a vite range change, and automatic rebases are disabled on this branch, so a reviewer cannot tell where this extra change came from or whether it is intended.
    Suggested fix / next action: if the vite patch is intentional (dev-only build tooling), add it to the PR title/body; otherwise revert that hunk and let the dedicated dependency PR carry it.

  • [Minor] The lockfile refresh surfaces a deprecation on the pinned @xmldom/xmldom version — the diff adds deprecated: this version has critical issues, please update to the latest version to the '@xmldom/xmldom@0.8.13' entry in pnpm-lock.yaml. The root package.json pins pnpm.overrides["@xmldom/xmldom@<0.8.13"] = "0.8.13", i.e. 0.8.13 is treated as the safe floor for older ranges; if upstream now flags 0.8.13 itself, that floor no longer protects anything. The yaml bump did not cause this — the regenerated lockfile only records the upstream metadata — and I could not verify the upstream advisory details in this run.
    Suggested fix / next action: check the upstream deprecation/advisory for @xmldom/xmldom@0.8.13 and, if a fixed 0.8.x release exists, raise the override floor; otherwise leave the pin and note why in the PR.

Questions

  • Was the vite ^7.3.2 → ^7.3.5 bump in apps/desktop/package.json intended as part of this change, or should it be split out?

Summary

Review mode: follow-up after new commits

  • packages/shared/package.json:20 bumps the exact-pinned yaml 2.8.4 → 2.9.0. The pin style, the permissive license (yaml is already a shipped dependency, so no license or ≤ 30 prod-dependency budget change), and the resolved version are all consistent. The two upstream 2.9.0 fixes (avoid Array.prototype.push.apply() with a large source array; avoid lexer recursion) are non-breaking, and the only documentation change is that parseDocument()/parseAllDocuments() no longer claim they never throw.
  • Every visible yaml consumer in the lockfile (the packages/shared importer plus the vite/vitest/vitepress peer suffixes) moves to 2.9.0 consistently.
  • The previous review's open question still stands and is unchanged by the new commits: yaml@2.8.4 remains in both the packages: and snapshots: sections of pnpm-lock.yaml with no visible referrer. Non-blocking; if a fresh pnpm install keeps it, it is a transitive pin and harmless.
  • The lockfile also carries unrelated re-resolution noise (@babel/* 7.29.7, @napi-rs/wasm-runtime 1.1.5, rollup 4.62.0), normal for a Dependabot pnpm lockfile refresh but worth a skim before merge.
  • Residual risk: upstream notes a RangeError (call-stack exhaustion) is still reachable on malicious YAML input and is now tracked as a bug rather than a vulnerability. That only matters if Open CoDesign parses untrusted YAML; I did not trace every yaml call site under packages/shared in this run, and this diff adds no new parsing path.

No Blocker or Major findings.

Testing

Not run (automation). Existing CI (pnpm lint, pnpm typecheck, pnpm test) covers this change; a dependency bump plus lockfile refresh does not warrant new Vitest/Playwright coverage.

Open-CoDesign Bot

@github-actions github-actions Bot removed the area:desktop apps/desktop (Electron shell, renderer) label Sep 23, 2026
@Sun-sunshine06
Sun-sunshine06 enabled auto-merge (squash) September 23, 2026 09:58

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

No Blocker, Major, or Minor findings are introduced or directly triggered by this diff.

Summary

Review mode: follow-up after new commits

  • packages/shared/package.json:20 bumps the exact-pinned yaml from 2.8.4 to 2.9.0, and pnpm-lock.yaml moves every visible yaml consumer consistently — the packages/shared importer plus the vite, vitest, vitepress, electron-vite, and @vitejs/plugin-react peer suffixes all resolve yaml@2.9.0. Pin style, resolved version, and the fact that yaml is already a shipped dependency (no prod-dependency count change, no new license to review) are all consistent.
  • The upstream 2.9.0 changes are non-breaking: two internal fixes (avoid Array.prototype.push.apply() on a large source array; avoid lexer recursion) plus a documentation-only change noting that parseDocument()/parseAllDocuments() no longer claim to "never throw".
  • The previous review's two Minor findings no longer appear in this diff: the apps/desktop/package.json vite range change is gone, and no @xmldom/xmldom@0.8.13 deprecation line is introduced here. They appear resolved by the rebase onto current main.
  • Residual (non-blocking, carried over from the previous review and unchanged): yaml@2.8.4 entries remain in the packages: and snapshots: sections of pnpm-lock.yaml while direct and peer consumers moved to 2.9.0 (see the added yaml@2.9.0: {} snapshot alongside the retained yaml@2.8.4: {}). If a fresh pnpm install keeps them, they are a harmless transitive pin; no action is required for this bump.
  • Residual risk: upstream now classifies call-stack-exhaustion (RangeError) on malicious YAML input as a bug rather than a vulnerability. This only matters if Open CoDesign parses untrusted YAML, and this diff adds no new parsing path, so it is not a merge blocker.
  • Note on the compare-since-previous-review output: it contains unrelated files (.changeset/requesty-proxy-preset.md, packages/shared/src/proxy-presets.{ts,test.ts}) that are not in this PR's changed-file list (packages/shared/package.json, pnpm-lock.yaml). Those look like base-branch commits pulled in by the rebase rather than part of this PR; no action requested.

The diff is internally consistent and ready to merge.

Testing

Not run (automation). A version bump plus lockfile refresh does not warrant new Vitest/Playwright coverage; existing CI (pnpm lint, pnpm typecheck, pnpm test) covers it.

Open-CoDesign Bot

@Sun-sunshine06
Sun-sunshine06 merged commit 2855c55 into main Sep 23, 2026
6 checks passed
@Sun-sunshine06
Sun-sunshine06 deleted the dependabot/npm_and_yarn/yaml-2.9.0 branch September 23, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:build Turbo/Vite/Biome/tsconfig toolchain chore Routine maintenance / non-feature work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant