Skip to content

fix(node-js-yaml): CVE-2025-64718#2

Open
deepin-ci-robot wants to merge 2 commits intomasterfrom
fix/CVE-2025-64718
Open

fix(node-js-yaml): CVE-2025-64718#2
deepin-ci-robot wants to merge 2 commits intomasterfrom
fix/CVE-2025-64718

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

Security Update

CVE-2025-64718: Fix prototype pollution in merge (<<) operator.


Generated by AI

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign qaqland for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 6, 2026

TAG Bot

TAG: 4.1.0+dfsg+_4.0.5-7deepin1
EXISTED: no
DISTRIBUTION: unstable

Fix prototype pollution in merge (<<) operator.

Upstream: nodeca/js-yaml@383665f

Generated-By: glm-5.1

Co-Authored-By: hudeng <hudeng@deepin.org>
The patch was missing the 'diff --git' header for test/issues/0164.js,
causing quilt to fail when applying patches. This fix adds the proper
git diff header.
@hudeng-go
Copy link
Copy Markdown

/integrate

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 9, 2026

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#3973
PrNumber: 3973
PrBranch: auto-integration-25593833948

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants