-
-
Notifications
You must be signed in to change notification settings - Fork 48
Closed
Labels
Description
A security concern was recently flagged for js-yaml package.
| Detail | Value |
|---|---|
| Severity | moderate |
| Description | js-yaml has prototype pollution in merge (<<) |
| Package | js-yaml |
| Vulnerable versions | >=4.0.0 <4.1.1 |
| Patched versions | >=4.1.1 |
| Paths | .>eslint-plugin-project-structure>js-yaml |
| More info | GHSA-mh29-5h37-fv8m |
Please publish a new version with an updated js-yaml version.
rakleed, ama-leanix, grig0ry and knorke132