Skip to content

chore(master): release 2.0.0 - #29

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
release-please--branches--master--components--load-nyc-config
Open

chore(master): release 2.0.0#29
github-actions[bot] wants to merge 1 commit into
masterfrom
release-please--branches--master--components--load-nyc-config

Conversation

@github-actions

@github-actions github-actions Bot commented Apr 9, 2026

Copy link
Copy Markdown

🤖 I have created a release beep boop

2.0.0 (2026-04-09)

⚠ BREAKING CHANGES

  • Update dependencies (requires node.js 20)

Bug Fixes

  • Update dependencies (requires node.js 20) (0a603e0)

This PR was generated with Release Please. See documentation.

@jwasnoggin

jwasnoggin commented Jun 16, 2026

Copy link
Copy Markdown

@coreyfarrell Would be great if this release can be published as it resolves GHSA-h67p-54hq-rp68

@GitHubNewbie0

Copy link
Copy Markdown

Thanks for pulling this together — the move to yaml and dropping js-yaml entirely is a clean resolution. Worth noting for anyone tracking this: 2.0.0 closes more than the prototype-pollution CVE in the existing issues. js-yaml ≤4.1.1 also carries CVE-2026-53550 (quadratic-complexity DoS via repeated merge-key aliases), and since this release removes js-yaml from the dependency entirely, it clears that one too. That's a second advisory off the board for every downstream consumer (babel-plugin-istanbul → test-exclude → load-nyc-config, etc.) once published. Would be great to see 2.0.0 tagged when you get a chance.

@thiagosan252

Copy link
Copy Markdown

@coreyfarrell when will this version be released? I'm also seeing this alert in my project.

@millansingh

Copy link
Copy Markdown

Also hoping to see a release here, so upstream deps can get updated and we can close out our CVEs.

@cgalvan

cgalvan commented Jun 25, 2026

Copy link
Copy Markdown

Is there an ETA for this release? My org has several vulnerabilities that are blocked by this as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants