Skip to content

chore(deps): root-cause track for yaml tooling chain#8

Merged
aretw0 merged 5 commits intodevelopfrom
chore/deps-tooling-yaml-root-cause
Apr 14, 2026
Merged

chore(deps): root-cause track for yaml tooling chain#8
aretw0 merged 5 commits intodevelopfrom
chore/deps-tooling-yaml-root-cause

Conversation

@aretw0
Copy link
Copy Markdown
Owner

@aretw0 aretw0 commented Apr 13, 2026

Refs #6. Root-cause iteration for @astrojs/check/yaml-language-server chain with full audit output.\n\n## What changed\n- aligned @astrojs/check to 0.9.2 in apps/dev and apps/me\n- refreshed lockfile\n\n## Validation\n- npm audit --omit=dev: 4 moderate, 0 high/critical\n- npm audit: 4 moderate, 0 high/critical\n- npm ls confirms remaining chain is yaml-language-server -> yaml@2.7.1\n\n## Note\nThis reduces risk surface but does not fully eliminate the moderate advisory chain yet.

@aretw0
Copy link
Copy Markdown
Owner Author

aretw0 commented Apr 13, 2026

Residual risk note before merge:\n\n- Remaining advisory: GHSA-48c2-rrv3-qjmp (moderate) in yaml tooling chain\n- Owner: @aretw0\n- Target date: 2026-04-20\n- Follow-up issue: will be created and linked in issue #6\n\nThis PR is intended to unblock CI convergence while follow-up hardening is executed with explicit tracking.

@aretw0 aretw0 merged commit 2311e0c into develop Apr 14, 2026
11 of 101 checks passed
@aretw0 aretw0 deleted the chore/deps-tooling-yaml-root-cause branch April 14, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant