-
-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security vulnerability at js-yaml #471
Comments
cosmiconfig seems to have upgraded to js-yml 3.13.0 in 5.2.0. |
This was referenced Apr 10, 2019
|
Thanks for letting me know. All dependencies have been updated in |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
@commitlint/load uses a vulnerable version of
cosmicconfig
andtslint
(which uses a vulnerable version ofjs-yml
), see https://nodesecurity.io/advisories/788 for more details on the security issue.js-yml
3.13.0 is patched, butcosmicconfig
andtslint
has yet to update its version.yarn audit
output:Expected Behavior
Use a patched version of
cosmicconfig
andtslint
when it's available, see this cosmicconfig issue & pr and this tslint issueCurrent Behavior
Uses a vulnerable version of
cosmiconfig
andtslint
The text was updated successfully, but these errors were encountered: