Skip to content

Bump js-yaml from 3.14.2 to 3.15.0 - #79644

Merged
desrosj merged 1 commit into
trunkfrom
dependabot/npm_and_yarn/js-yaml-3.15.0
Jun 30, 2026
Merged

desrosj merged 1 commit into
trunkfrom
dependabot/npm_and_yarn/js-yaml-3.15.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 3.14.2 to 3.15.0.

Changelog

Sourced from js-yaml's changelog.

4.3.0, 3.15.0 - 2026-06-27

Security

  • Backported maxTotalMergeKeys option.

[5.2.0] - 2026-06-26

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.
  • Added maxAliases (-1) loader option to limit the number of YAML aliases per document.

Removed

  • maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.

Fixed

  • Round-trip of integers with exponential form (>= 1e21)

[5.1.0] - 2026-06-23

Added

  • Collection tags can finalize an incrementally populated carrier into a different result value.

Changed

  • [breaking] quoteStyle now selects the preferred quote style; use the restored forceQuotes option to force quoting non-key strings.

[5.0.0] - 2026-06-20

Added

  • Added named exports for schemas, tags, parser events and AST utilities.
  • Reworked JSON_SCHEMA and CORE_SCHEMA with spec-compliant scalar resolution rules, and added YAML11_SCHEMA.
  • Added realMapTag for lossless mappings with non-string and complex keys. Object-based mappings now reject complex keys instead of stringifying them.
  • Added dump() transform option for changing the generated AST before rendering.
  • Added dump() options seqInlineFirst, flowBracketPadding, flowSkipCommaSpace, flowSkipColonSpace, quoteFlowKeys, quoteStyle and tagBeforeAnchor.
  • Added formal data layers (events and AST) for modular data pipelines.
    • Added low-level parser (to events), presenter and visitor APIs.
  • Added the YAML Test Suite to the test set.

Changed

  • See the migration guide for upgrade notes.
  • Rewritten in TypeScript and reorganized the public API around flat named exports.

... (truncated)

Commits

@dependabot dependabot Bot added [Type] Build Tooling Issues or PRs related to build tooling dependencies Pull requests that update a dependency file labels Jun 29, 2026
@dependabot
dependabot Bot requested a review from t-hamano as a code owner June 29, 2026 17:55
@dependabot dependabot Bot added [Type] Build Tooling Issues or PRs related to build tooling dependencies Pull requests that update a dependency file labels Jun 29, 2026
@github-actions

ghost commented Jun 29, 2026 •

Copy link
Copy Markdown

Size Change: 0 B

Total Size: 7.61 MB

compressed-size-action

@github-actions

ghost commented Jun 29, 2026

Copy link
Copy Markdown

Flaky tests detected in ed4b971.
Some tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information.

🔍 Workflow run URL: https://github.com/WordPress/gutenberg/actions/runs/28392143252
📝 Reported issues:

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.2 to 3.15.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/js-yaml-3.15.0 branch from ed4b971 to 25cde2d Compare June 30, 2026 08:40
@desrosj

ghost commented Jun 30, 2026

Copy link
Copy Markdown
Member

@copilot Analyze how js-yaml is used in this repository and determine whether the changes in this update affect that usage in any way.

Additionally, evaluate whether this dependency is even required at all or can be dropped in favor of some native feature, or if the functionality is duplicated by another dependency.

@github-actions

ghost commented Jun 30, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: desrosj <desrosj@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

ghost commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

@copilot Analyze how js-yaml is used in this repository and determine whether the changes in this update affect that usage in any way.

Additionally, evaluate whether this dependency is even requi...

Usage analysis

js-yaml is used in exactly one place: packages/env/lib/runtime/docker/docker-config.js. The only call is yaml.dump(dockerComposeConfig) (line 37), which serializes a JavaScript config object to YAML to write the docker-compose.yml file that wp-env uses to launch its Docker environment.

Impact of 3.14.2 → 3.15.0

The sole change in 3.15.0 is a security backport of the maxTotalMergeKeys loader option — it caps the total number of keys processed by YAML merge (<<) across a single load() / loadAll() call to guard against DoS via crafted merge-heavy YAML. This repository never calls load() or loadAll(); only dump() is used. The update has no functional impact on this codebase, though taking the security fix as a patch is still the right call.

Can js-yaml be dropped?

Not at this time:

  • Node.js has no native YAML serializer, so there is no built-in alternative.
  • No other dependency in packages/env or the broader monorepo already provides dump()-style YAML output that could replace it.
  • The dependency is genuinely required to produce a valid docker-compose.yml.

One longer-term option worth noting: js-yaml v3 is now at its final release (3.15.0 is the last planned v3 tag — the project has moved to v4/v5). Upgrading to v4 would be the natural next step for @wordpress/env eventually, since v4 removed the unsafe legacy tags and cleaned up the API, but that's a separate, deliberate change rather than something that falls out of this bump.

Copilot Bot requested a review from desrosj June 30, 2026 13:55
@desrosj
desrosj merged commit 37aa21f into trunk Jun 30, 2026
@desrosj
desrosj deleted the dependabot/npm_and_yarn/js-yaml-3.15.0 branch June 30, 2026 15:42
@github-actions github-actions Bot added this to the Gutenberg 23.6 milestone Jun 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file [Type] Build Tooling Issues or PRs related to build tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants