From 80d038384cb4c34cc97225aebd1f4ec45c60f1ca Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 20 Nov 2025 09:46:32 +0000 Subject: [PATCH] fix: script/validate-data/package.json & script/validate-data/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-13961110 --- script/validate-data/package-lock.json | 15 ++++++++------- script/validate-data/package.json | 2 +- 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/script/validate-data/package-lock.json b/script/validate-data/package-lock.json index 358c6615bd..98742ca0bb 100644 --- a/script/validate-data/package-lock.json +++ b/script/validate-data/package-lock.json @@ -10,7 +10,7 @@ "license": "MIT", "dependencies": { "@actions/core": "^1.9.1", - "js-yaml": "^3.13.1", + "js-yaml": "^3.14.2", "jsonschema": "^1.2.6" }, "devDependencies": { @@ -91,9 +91,10 @@ } }, "node_modules/js-yaml": { - "version": "3.13.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.13.1.tgz", - "integrity": "sha512-YfbcO7jXDdyj0DGxYVSlSeQNHbD7XPWvrVWeVUujrQEoZzWJIRrCPoyk6kL6IAjAG2IolMK4T0hNUe0HOUs5Jw==", + "version": "3.14.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", + "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", + "license": "MIT", "dependencies": { "argparse": "^1.0.7", "esprima": "^4.0.0" @@ -266,9 +267,9 @@ "integrity": "sha512-eGuFFw7Upda+g4p+QHvnW0RyTX/SVeJBDM/gCtMARO0cLuT2HcEKnTPvhjV6aGeqrCB/sbNop0Kszm0jsaWU4A==" }, "js-yaml": { - "version": "3.13.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.13.1.tgz", - "integrity": "sha512-YfbcO7jXDdyj0DGxYVSlSeQNHbD7XPWvrVWeVUujrQEoZzWJIRrCPoyk6kL6IAjAG2IolMK4T0hNUe0HOUs5Jw==", + "version": "3.14.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", + "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", "requires": { "argparse": "^1.0.7", "esprima": "^4.0.0" diff --git a/script/validate-data/package.json b/script/validate-data/package.json index 6811f19edb..c186d66a96 100644 --- a/script/validate-data/package.json +++ b/script/validate-data/package.json @@ -15,7 +15,7 @@ }, "dependencies": { "@actions/core": "^1.9.1", - "js-yaml": "^3.13.1", + "js-yaml": "^3.14.2", "jsonschema": "^1.2.6" } } \ No newline at end of file