js-yaml@4.1.0 in this project has a known prototype pollution vulnerability (CWE-1321, CVSS 6.9). Upgrading to 4.1.1 fixes it with no breaking changes.
Verified: pnpm add js-yaml@latest + pnpm run build produces a working plugin.
Detected via Snyk.io