Repository navigation
chore(deps): bump yaml from 2.8.4 to 2.9.0 - #360
Conversation
Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.4 to 2.9.0. - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.8.4...v2.9.0) --- updated-dependencies: - dependency-name: yaml dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.5. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v7.3.5/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 7.3.5 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Findings
No issues found. This is a correctly-scoped, single-dependency bump that only touches packages/shared/package.json and pnpm-lock.yaml.
packages/shared/package.json:20— bumpsyaml2.8.4→2.9.0, preserving the exact-pin convention already used for this dependency. No new dependency is introduced, so the ≤ 30 prod-dependency budget is unaffected;yamlwas already a shipped dependency (permissive/ISC), so the MIT-compatible shipped-dependency constraint does not change.pnpm-lock.yaml— thepackages/sharedimporter, the newyaml@2.9.0packages:/snapshots:entries, and theyamlpeer suffixes forvite/vitest/vitepressare all updated consistently to2.9.0. The two upstream 2.9.0 fixes (Array.prototype.push.apply()with large source arrays, lexer call-stack recursion) are non-breaking per the release notes.- No application source files changed, so no new Vitest/Playwright coverage is warranted for this diff.
Questions
pnpm-lock.yamlretains theyaml@2.8.4entry in both thepackages:andsnapshots:sections even though the visible reference sites (thepackages/sharedimporter plus everyvite/vitest/vitepresspeer suffix) move to2.9.0. Isyaml@2.8.4still resolved transitively, or should those entries be pruned by a freshpnpm install?
Summary
Review mode: initial
Routine Dependabot bump of yaml 2.8.4 → 2.9.0, limited to packages/shared/package.json and pnpm-lock.yaml. No code paths changed, no new dependency added, permissive license preserved, and the version is pinned consistently with the prior entry. No Blocker/Major/Minor findings.
Residual observation: the lockfile keeps a yaml@2.8.4 entry alongside the newly added yaml@2.9.0. This is harmless if yaml@2.8.4 is still pulled in transitively; if it is not, a re-run of pnpm install would prune it. pnpm lint && pnpm typecheck && pnpm test on CI should confirm nothing regressed.
Testing
Not run (automation). Existing CI (pnpm lint, pnpm typecheck, pnpm test) covers this change; a dependency bump alone does not require new tests.
Open-CoDesign Bot
There was a problem hiding this comment.
Findings
-
[Minor] Title/body vs. diff scope mismatch — the PR is described as
yaml2.8.4 → 2.9.0 only, but the diff also raises the desktop app'svitedevDependency from^7.3.2to^7.3.5(apps/desktop/package.json:64), which pullsrollup@4.60.2 → 4.62.0,postcss@8.5.15, andtinyglobby@0.2.17into that resolution (pnpm-lock.yaml). Nothing in theyamlbump requires aviterange change, and automatic rebases are disabled on this branch, so a reviewer cannot tell where this extra change came from or whether it is intended.
Suggested fix / next action: if thevitepatch is intentional (dev-only build tooling), add it to the PR title/body; otherwise revert that hunk and let the dedicated dependency PR carry it. -
[Minor] The lockfile refresh surfaces a deprecation on the pinned
@xmldom/xmldomversion — the diff addsdeprecated: this version has critical issues, please update to the latest versionto the'@xmldom/xmldom@0.8.13'entry inpnpm-lock.yaml. The rootpackage.jsonpinspnpm.overrides["@xmldom/xmldom@<0.8.13"] = "0.8.13", i.e. 0.8.13 is treated as the safe floor for older ranges; if upstream now flags 0.8.13 itself, that floor no longer protects anything. Theyamlbump did not cause this — the regenerated lockfile only records the upstream metadata — and I could not verify the upstream advisory details in this run.
Suggested fix / next action: check the upstream deprecation/advisory for@xmldom/xmldom@0.8.13and, if a fixed 0.8.x release exists, raise the override floor; otherwise leave the pin and note why in the PR.
Questions
- Was the
vite^7.3.2→^7.3.5bump inapps/desktop/package.jsonintended as part of this change, or should it be split out?
Summary
Review mode: follow-up after new commits
packages/shared/package.json:20bumps the exact-pinnedyaml2.8.4→2.9.0. The pin style, the permissive license (yamlis already a shipped dependency, so no license or ≤ 30 prod-dependency budget change), and the resolved version are all consistent. The two upstream 2.9.0 fixes (avoidArray.prototype.push.apply()with a large source array; avoid lexer recursion) are non-breaking, and the only documentation change is thatparseDocument()/parseAllDocuments()no longer claim they never throw.- Every visible
yamlconsumer in the lockfile (thepackages/sharedimporter plus thevite/vitest/vitepresspeer suffixes) moves to 2.9.0 consistently. - The previous review's open question still stands and is unchanged by the new commits:
yaml@2.8.4remains in both thepackages:andsnapshots:sections ofpnpm-lock.yamlwith no visible referrer. Non-blocking; if a freshpnpm installkeeps it, it is a transitive pin and harmless. - The lockfile also carries unrelated re-resolution noise (
@babel/*7.29.7,@napi-rs/wasm-runtime1.1.5,rollup4.62.0), normal for a Dependabot pnpm lockfile refresh but worth a skim before merge. - Residual risk: upstream notes a
RangeError(call-stack exhaustion) is still reachable on malicious YAML input and is now tracked as a bug rather than a vulnerability. That only matters if Open CoDesign parses untrusted YAML; I did not trace everyyamlcall site underpackages/sharedin this run, and this diff adds no new parsing path.
No Blocker or Major findings.
Testing
Not run (automation). Existing CI (pnpm lint, pnpm typecheck, pnpm test) covers this change; a dependency bump plus lockfile refresh does not warrant new Vitest/Playwright coverage.
Open-CoDesign Bot
There was a problem hiding this comment.
Findings
No Blocker, Major, or Minor findings are introduced or directly triggered by this diff.
Summary
Review mode: follow-up after new commits
packages/shared/package.json:20bumps the exact-pinnedyamlfrom2.8.4to2.9.0, andpnpm-lock.yamlmoves every visibleyamlconsumer consistently — thepackages/sharedimporter plus thevite,vitest,vitepress,electron-vite, and@vitejs/plugin-reactpeer suffixes all resolveyaml@2.9.0. Pin style, resolved version, and the fact thatyamlis already a shipped dependency (no prod-dependency count change, no new license to review) are all consistent.- The upstream 2.9.0 changes are non-breaking: two internal fixes (avoid
Array.prototype.push.apply()on a large source array; avoid lexer recursion) plus a documentation-only change noting thatparseDocument()/parseAllDocuments()no longer claim to "never throw". - The previous review's two Minor findings no longer appear in this diff: the
apps/desktop/package.jsonviterange change is gone, and no@xmldom/xmldom@0.8.13deprecation line is introduced here. They appear resolved by the rebase onto currentmain. - Residual (non-blocking, carried over from the previous review and unchanged):
yaml@2.8.4entries remain in thepackages:andsnapshots:sections ofpnpm-lock.yamlwhile direct and peer consumers moved to2.9.0(see the addedyaml@2.9.0: {}snapshot alongside the retainedyaml@2.8.4: {}). If a freshpnpm installkeeps them, they are a harmless transitive pin; no action is required for this bump. - Residual risk: upstream now classifies call-stack-exhaustion (
RangeError) on malicious YAML input as a bug rather than a vulnerability. This only matters if Open CoDesign parses untrusted YAML, and this diff adds no new parsing path, so it is not a merge blocker. - Note on the compare-since-previous-review output: it contains unrelated files (
.changeset/requesty-proxy-preset.md,packages/shared/src/proxy-presets.{ts,test.ts}) that are not in this PR's changed-file list (packages/shared/package.json,pnpm-lock.yaml). Those look like base-branch commits pulled in by the rebase rather than part of this PR; no action requested.
The diff is internally consistent and ready to merge.
Testing
Not run (automation). A version bump plus lockfile refresh does not warrant new Vitest/Playwright coverage; existing CI (pnpm lint, pnpm typecheck, pnpm test) covers it.
Open-CoDesign Bot
Bumps yaml from 2.8.4 to 2.9.0.
Release notes
Sourced from yaml's releases.
Commits
ddb21b02.9.0167365bdocs: Clarify that not all errors can be avoided6eca2a7fix: Avoid calling Array.prototype.push.apply() with large source array0543cd5fix(lexer): Avoid recursive calls that may exhaust the call stackYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)