descriptinc / descriptinc/dependicus
[Dependicus] [npm] FYI: js-yaml 5.4.2 is available (currently on 4.1.1)
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 11
- Forks
- 1
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 5
Description
YAML 1.2 parser and serializer
Summary
- Current version:
4.1.1(published 2025-11-12) - Target version:
5.4.2(published 2026-09-13) - Update type: major
- Versions behind: 14
- Installed size: 386.3 kB
- Dependency types: prod
- In catalog: No
How to Update
This dependency is used by 5 packages. Consider adding it to the catalog:
- Add to catalog - Edit
undefined:
catalog:
js-yaml: 5.4.2
-
Update each package to use
"js-yaml": "catalog:"instead of the version number. -
Run
pnpm installto update the lockfile.
Packages to update:
@dependicus/core@dependicus/providers-nodedependicusdependicus-monorepopackages/dependicus
Alternatively, update each package to "js-yaml": "5.4.2" individually.
Upgrade Path
- 5.4.2 (latest) (2026-09-13) — 1.6 MB (+307%)
- 5.4.1 (2026-08-26) — 1.6 MB (+307%)
- 5.4.0 (2026-08-25) — 1.6 MB (+306%)
- 5.3.0 (2026-08-14) — 1.6 MB (+303%)
- 5.2.3 (2026-08-01) — 1.5 MB (+276%)
- 5.2.2 (2026-07-23) — 1.4 MB (+273%)
- 5.2.1 (2026-07-02) — 1.4 MB (+273%)
- 5.2.0 (2026-06-26) — 1.4 MB (+272%)
- 5.1.0 (2026-06-22) — 1.4 MB (+270%)
- 5.0.0 (2026-06-20) — 1.4 MB (+266%)
- 4.3.2 (2026-08-26) — 960.2 kB (+149%)
- 4.3.1 (2026-07-31) — 958.0 kB (+148%)
- 4.3.0 (2026-06-26) — 957.6 kB (+148%)
- 4.2.0 (2026-05-31) — 874.0 kB (+126%)
Links
Notes for coding agents
PR title should be: "Update js-yaml from 4.1.1 to 5.4.2"
If the PR body makes claims about the changes in the new version, include URL references to release notes, changelogs, or commit diffs that support those claims.
This issue was automatically created by Dependicus. It will be recreated if closed while the dependency remains non-compliant.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Inspect the dependency declarations for @dependicus/core, @dependicus/providers-node, dependicus, dependicus-monorepo, and packages/dependicus. Review the js-yaml 4.1.1 to 5.4.2 upgrade path, then choose the catalog or individual-update approach and run pnpm install. Done means all five packages use the target version and the lockfile is updated.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, typescript
- Domain
- build-system, tooling
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100