Skip to content

chore(deps): bump yaml from 1.10.2 to 1.10.3#7398

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/yaml-1.10.3
Open

chore(deps): bump yaml from 1.10.2 to 1.10.3#7398
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/yaml-1.10.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 26, 2026

Bumps yaml from 1.10.2 to 1.10.3.

Commits
  • cfe8f04 1.10.3
  • 7abcf45 fix: Catch stack overflow during CST composition
  • a0252f8 chore: Add rules avoiding processing of tests/json-test-suite
  • a5e83b0 style: Apply updates Prettier rules
  • b8ddca0 chore: Refresh lockfile
  • 395f892 ci: Use a different (working) submodule checkout
  • 6fd2720 test-events: Add {} and [] indicators to flow maps & sequences
  • See full diff in compare view

@dependabot dependabot bot added dependencies javascript Pull requests that update javascript code labels Mar 26, 2026
Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c4b379c34c

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

resolution: "@accruals-gateway/domains@link:./domains::locator=%40app%2Faccruals-gateway%40workspace%3Aapps%2Faccruals-gateway"
languageName: node
linkType: soft

"@address-service/domains@link:./domains::locator=%40app%2Faddress-service%40workspace%3Aapps%2Faddress-service":
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate lockfile with full workspace set

This change is not limited to the yaml bump: it also drops thousands of unrelated lockfile entries, including many @app/* workspace stanzas (the first disappearance is immediately before this line). In a full monorepo checkout (root package.json still uses "workspaces": ["apps/*", "packages/*"]), those missing workspace sections will be reintroduced, causing yarn install --immutable failures or large unrelated lockfile churn; please regenerate yarn.lock from a complete workspace checkout so only the intended dependency update is included.

Useful? React with 👍 / 👎.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from c4b379c to 0beb150 Compare March 29, 2026 08:02
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from 0beb150 to 9d5a6ec Compare March 29, 2026 18:09
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from 9d5a6ec to 33f4e63 Compare March 30, 2026 06:12
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from 33f4e63 to bf7a5fb Compare March 30, 2026 07:01
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from bf7a5fb to 9684981 Compare April 2, 2026 14:03
Bumps [yaml](https://github.com/eemeli/yaml) from 1.10.2 to 1.10.3.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v1.10.2...v1.10.3)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 1.10.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/yaml-1.10.3 branch from 9684981 to e89b312 Compare April 8, 2026 13:09
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 8, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants