import-sort
import-sort copied to clipboard
Bump js-yaml from 3.12.1 to 3.13.1
Bumps js-yaml from 3.12.1 to 3.13.1.
Changelog
Sourced from js-yaml's changelog.
3.13.1 / 2019-04-05
- Fix possible code execution in (already unsafe)
.load(), #480.3.13.0 / 2019-03-20
- Security fix:
safeLoad()can hang when arrays with nested refs used as key. Now throws exception for nested arrays. #475.3.12.2 / 2019-02-26
- Fix
noArrayIndentoption for root level, #468.
Commits
665aadd3.13.1 releasedda8ecf2Browser files rebuildb2f9e88Merge pull request #480 from nodeca/toStringe18afbfFix possible code execution in (already unsafe) load()9d4ce5e3.13.0 releasedf64c673Browser files rebuilda567ef3Restrict data types for object keys59b6e76Fix test namee4267fc3.12.2 released7231a49Browser files rebuild- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language