js-yaml has prototype pollution in merge

This commit is contained in:
Andrii Kurdiumov
2026-01-17 09:33:47 +01:00
parent 3f193c7948
commit ab52ae20d7
+5 -4
View File
@@ -6,7 +6,7 @@
"packages": {
"": {
"name": "xlsx-template",
"version": "1.4.5",
"version": "1.4.7",
"license": "MIT",
"dependencies": {
"@kant2002/jszip": "2.7.1",
@@ -2933,10 +2933,11 @@
"license": "MIT"
},
"node_modules/js-yaml": {
"version": "3.14.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.1.tgz",
"integrity": "sha512-okMH7OXXJ7YrN9Ok3/SXrnu4iX9yOk+25nqX4imS2npuvTYDmo/QEZoqwZkYaIDk3jVvBOTOIEgEhaLOynBS9g==",
"version": "3.14.2",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz",
"integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==",
"dev": true,
"license": "MIT",
"dependencies": {
"argparse": "^1.0.7",
"esprima": "^4.0.0"