chore(security): defer js-yaml remediation until September 10 - #11254
chore(security): defer js-yaml remediation until September 10#11254rsliter wants to merge 1 commit into
Conversation
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 12 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe checked-in npm audit policy adds a temporary exception for Changesnpm audit policy
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This change records a bounded temporary js-yaml audit exception and preserves validation that the prior brace-expansion exception is removed. No merge-blocking implementation risk remains. Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 994a822 in the TypeScript / code-coverage/cliThe overall line coverage in commit 994a822 in the Show a line coverage summary of the most impacted files.
Updated |
Outcome
Temporarily accept GHSA-2883-xcg3-v3hh for js-yaml 4.3.1 in the CLI production graph through September 10, 2026 UTC. Keep the dependency upgrade deferred from v0.0.121.
Reason
The refreshed release image audit blocks on this advisory. The maintainer accepted the risk temporarily while the upgrade remains tracked separately.
Related issues
Refs #11252.
Changes
Verification
npm run validate:pr: passed against canonical main 7c54bc0 after building CLI and plugin prerequisites.Review notes
Maintainer risk acceptance: #11252 (comment). The authenticated author rsliter had MAINTAIN permission when this record was created. This exception does not waive image publication, E2E decisions, or release confirmation. Independent PR review remains pending.
Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com
Summary by CodeRabbit
Security
Tests