Skip to content

Conversation

@jeffabailey
Copy link
Collaborator

Added package override to ensure js-yaml version 3.14.2+ is used,
addressing a moderate severity security vulnerability in the transitive
dependency. Also fixed brace-expansion vulnerability via npm audit fix.

Added package override to ensure js-yaml version 3.14.2+ is used,
addressing a moderate severity security vulnerability in the transitive
dependency. Also fixed brace-expansion vulnerability via npm audit fix.
@jeffabailey jeffabailey requested a review from a team as a code owner November 26, 2025 14:05
@dellagustin-sap dellagustin-sap self-assigned this Nov 26, 2025
Copy link
Contributor

@dellagustin-sap dellagustin-sap left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I cloned the repository, checked out this branch and run the instructions on scripts/gqm_gen/README.md (https://github.com/InnerSourceCommons/managing-innersource-projects/blob/93090e31c001e2a76fa03efab7262a4a964b0f1e/scripts/gqm_gen/README.md).

It updated the measuring/use_gqm.md file.
Note that I did not see the new files described in the Usage section of the README.md, but I'm assuming this is not a side effect of this change, rather either a misunderstanding on my end, or the documentation is outdated.

So, looks good to me.

@dellagustin-sap
Copy link
Contributor

@jeffabailey , no sure if you expected the reviewer to merge it after approving, so I'm leaving the merge to you.

@jeffabailey jeffabailey merged commit eaa9eb9 into main Nov 27, 2025
1 check passed
@jeffabailey jeffabailey deleted the claude/fix-js-yaml-vulnerability-01FzKxYG3XzLWBQ4Hgo8SSke branch November 27, 2025 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants