Could be there a patch with the vulnerability fix for yaml@1.10.2
?
#469
-
Hi! Wondering if you plan to do a patch to fix the vulnerability in Yaml@1.10.2 so we can apply a resolution to transitive dependencies installing the old version 🙏 |
Beta Was this translation helpful? Give feedback.
Answered by
eemeli
Apr 25, 2023
Replies: 1 comment 1 reply
-
|
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
eemeli
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
yaml@1
is not affected by this vulnerability, and does not need to be patched. A freshnpm audit
should show it passing. The version range has also been updated at least on GitHub: GHSA-f9xv-q969-pqx4