Skip to content

chore(deps): bump js-yaml and @nestjs/swagger - #803

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-ff587ed403
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-ff587ed403

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps js-yaml to 5.4.2 and updates ancestor dependency @nestjs/swagger. These dependencies need to be updated together.

Updates js-yaml from 5.3.0 to 5.4.2

Changelog

Sourced from js-yaml's changelog.

[5.4.2] - 2026-09-13

Fixed

  • forceQuotes no longer quotes non-string scalars, #798.

[5.4.1] - 2026-08-26

Changed

  • Hard-limit merge sequence size to 100.

Security

  • Count empty mappings in merge sequences toward maxTotalMergeKeys to limit CPU usage, #797.

[5.4.0] - 2026-08-25

Added

  • Added the scalarStyleRules dumper option to customize string formatting. See Scalar styling for details.

Changed

  • [breaking] Flattened the low-level AST node style representation. Scalar and collection nodes now use SCALAR_STYLE and COLLECTION_STYLE values; explicit tags use the separate tagged property. Alias nodes now contain only kind and anchor. This only affects code that directly constructs or edits AST nodes.
  • [breaking] The sortKeys option was rewritten using AST mutation to avoid side effects.
  • Reworked scalar style selection. This can change formatting without changing loaded values; in particular, whitespace-only strings are now double-quoted.

Fixed

  • Accept a byte order mark at the start of each document in a stream, #791.
  • Produce valid flow mappings with quoteFlowKeys and flowSkipColonSpace, including alias and property-only keys, #786.
  • Preserve empty scalar items when converting block sequences to flow style.
  • Do not apply the 1024-character simple-key limit to flow mapping keys.
  • Count Unicode code points, rather than UTF-16 code units, for the 1024-character simple-key limit.
  • Add an explicit document-end marker after keep-chomped block scalars when needed to preserve trailing newlines.
Commits

Updates @nestjs/swagger from 11.4.7 to 12.0.2

Release notes

Sourced from @​nestjs/swagger's releases.

12.0.2

What's Changed

New Contributors

Full Changelog: nestjs/swagger@12.0.1...12.0.2

Release 12.0.1

12.0.1 (2026-08-28)

Bug fixes

Dependencies

Committers: 1

Release 12.0.0

What's Changed

@nestjs/swagger is now a native ES module, requires Nest 12, and changes how nullable schemas are spelled in the generated document.

ESM migration

The package is published as pure ESM ("type": "module", compiled with NodeNext) behind a proper exports map. The legacy root index.ts / plugin.js / plugin.ts shims are gone, and deep imports into build internals are no longer resolvable — import from the package root (@nestjs/swagger) or from @nestjs/swagger/plugin.

require(esm) — CommonJS still works

You do not need to convert your app to ESM. Thanks to Node's require(esm) support, a CommonJS app can keep doing const { SwaggerModule } = require('@nestjs/swagger'). The CLI plugin entry (@nestjs/swagger/plugin) also keeps a require condition so nest-cli.json setups load it unchanged.

This is why the package now declares "engines": { "node": "^20.19.0 || >=22.12.0" } — those are the Node versions where require(esm) is available without a flag.

... (truncated)

Commits
  • 8f00eb9 chore(): release v12.0.2
  • bfb2315 fix(swagger-ui): preserve $ characters when building swagger-ui-init.js (#4119)
  • 2bea96a feat: support the HTTP QUERY method (RFC 10008) (#4007)
  • 752e5c7 chore(deps): update dependency supertest to v7.3.0 (#4142)
  • 4faed70 fix(deps): update dependency @​microsoft/tsdoc to v0.17.0 (#4124)
  • d0e7976 fix(deps): update dependency swagger-ui-dist to v5.33.0 (#4128)
  • abce2be fix: declare typescript as an optional peer dependency (#4134)
  • 234c20c fix(standard-schema): promote schema description to parameter object (#4140)
  • 9652868 chore(deps): update dependency oxlint to v1.85.0 (#4141)
  • 92ee181 chore(deps): update nest monorepo to v12.0.4 (#4138)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [js-yaml](https://github.com/nodeca/js-yaml) to 5.4.2 and updates ancestor dependency [@nestjs/swagger](https://github.com/nestjs/swagger). These dependencies need to be updated together.


Updates `js-yaml` from 5.3.0 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.3.0...5.4.2)

Updates `@nestjs/swagger` from 11.4.7 to 12.0.2
- [Release notes](https://github.com/nestjs/swagger/releases)
- [Commits](nestjs/swagger@11.4.7...12.0.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: indirect
- dependency-name: "@nestjs/swagger"
  dependency-version: 12.0.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from keysersoft as a code owner September 30, 2026 07:28
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@github-actions github-actions Bot added the needs-review PR requires manual human review (e.g. major bumps, runtime changes) label Sep 30, 2026
@github-actions

Copy link
Copy Markdown

Skipping auto-merge: not-patch-or-minor (version-update:semver-major). A human should review this bump.

@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-ff587ed403 branch September 30, 2026 20:39
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file needs-review PR requires manual human review (e.g. major bumps, runtime changes)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants