Skip to content

Combine @babel/preset-env 7.24.5 and js-yaml security upgrades into single PR - #98

Merged
ahernandez411 merged 2 commits into
dependabot/npm_and_yarn/babel/preset-env-7.24.5from
copilot/sub-pr-84
Mar 6, 2026
Merged

Combine @babel/preset-env 7.24.5 and js-yaml security upgrades into single PR#98
ahernandez411 merged 2 commits into
dependabot/npm_and_yarn/babel/preset-env-7.24.5from
copilot/sub-pr-84

Conversation

Copilot AI commented Mar 6, 2026

Copy link
Copy Markdown

PRs #84 and #91 were both failing and causing conflicts when fixed separately. This PR consolidates both dependency upgrades into a single change.

Changes

  • @babel/preset-env bumped from 7.23.97.24.5
  • js-yaml bumped from 4.1.04.1.1 and 3.14.13.14.2 — fixes prototype pollution via the yaml merge (<<) operator (security fix)
  • All 8 affected js-yaml entries updated across both node_modules and legacy dependency sections in package-lock.json

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Co-authored-by: ahernandez411 <11199284+ahernandez411@users.noreply.github.com>
Copilot AI changed the title [WIP] Update @babel/preset-env to version 7.24.5 Combine @babel/preset-env 7.24.5 and js-yaml security upgrades into single PR Mar 6, 2026
@github-actions

github-actions Bot commented Mar 6, 2026

Copy link
Copy Markdown

Next Version: v1.1.14

@ahernandez411
ahernandez411 marked this pull request as ready for review March 6, 2026 21:55
@ahernandez411
ahernandez411 requested review from a team and bradyclifford as code owners March 6, 2026 21:55
@ahernandez411
ahernandez411 merged commit 1d3a94e into dependabot/npm_and_yarn/babel/preset-env-7.24.5 Mar 6, 2026
4 checks passed
@ahernandez411
ahernandez411 deleted the copilot/sub-pr-84 branch March 6, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants