Some of the audit tools have been falsely flagging the alias to `@zkochan/js-yaml` as `js-yaml@0.0.7` (which has security holes) so we decided to use the package explicitly. ## Current Behavior <!-- This is the behavior we have today --> ## Expected Behavior <!-- This is the behavior we should expect with the changes in this PR --> ## Related Issue(s) <!-- Please link the issue being fixed so it gets closed when this is merged. --> Fixes #