Files
langgraph/libs
ea20432b9b fix: bump js-yaml to 3.14.2 to resolve CVE-2025-64718 (#6879)
## Security Alert Patch

Resolves 1 Dependabot security alert (medium severity).

### Package Updated

| Package | Old Version | New Version | Strategy | CVE Resolved |
|---------|-------------|-------------|----------|--------------|
| `js-yaml` | 3.14.1 | 3.14.2 | Lockfile patch (within-range bump) |
CVE-2025-64718 |

### CVE Details

**CVE-2025-64718** /
[GHSA-mh29-5h37-fv8m](https://github.com/advisories/GHSA-mh29-5h37-fv8m)
— `js-yaml` prototype pollution via YAML merge keys (`<<`). Affects
versions < 3.14.2.

The vulnerable package is a transitive dev dependency pulled in by
`@istanbuljs/load-nyc-config@1.1.0` (a Jest internal). No runtime
impact.

### Fix Strategy

Lockfile-only patch in `libs/cli/js-examples/yarn.lock`. The `^3.13.1`
version range already allows 3.14.2, so no manifest changes were needed.
The `js-yaml@^4.1.1` entry (used by `@eslint/eslintrc`) is untouched.

### Verification

- [x] Lockfile updated — `js-yaml@^3.13.1` now resolves to `3.14.2`
- [x] `js-yaml@^4.1.1` entry unchanged (`4.1.1`)
- [x] `yarn install --frozen-lockfile` passes

🤖 Submitted by langster-patch

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-19 19:41:51 +00:00
..
2026-02-19 11:10:19 -08:00