Skip to content

Update js-yaml to 4.1.1 to address security vulnerability CVE-2025-64718 #1975

@possible-evan

Description

@possible-evan

See vulnerability here https://avd.aquasec.com/nvd/2025/cve-2025-64718/

yarn why js-yaml

├─ @datadog/datadog-ci@npm:4.1.3
│  └─ js-yaml@npm:3.13.1 (via npm:3.13.1)

This package is using 3.x. 4.x has been patched but 3.x has not yet. A request for 3.x to be patched has been submitted here nodeca/js-yaml#730

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions