Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Npm audit js-yaml HIgh vulnerability #8338

Closed
ghost opened this issue Apr 17, 2019 · 4 comments
Closed

Npm audit js-yaml HIgh vulnerability #8338

ghost opened this issue Apr 17, 2019 · 4 comments

Comments

@ghost
Copy link

ghost commented Apr 17, 2019

High Code Injection
Package js-yaml
Dependency of jest
Path jest > jest-cli > @jest/core > @jest/reporters > istanbul-api > js-yaml
More info https://npmjs.com/advisories/813
@SimenB
Copy link
Member

SimenB commented Apr 17, 2019

Report it to istanbul, this is transitive for jest (but note that istanbul-api is gonna be deprecated (istanbuljs/istanbuljs#321))

@SimenB SimenB closed this as completed Apr 17, 2019
@coreyfarrell
Copy link
Contributor

Also note that istanbul-api depends on js-yaml ^3.13.0 which allows the non-vulnerable version to be installed so the issue is likely that your package-lock.json or yarn.lock needs to be regenerated.

@ghost
Copy link
Author

ghost commented Apr 23, 2019

Okay, thank you.

@github-actions
Copy link

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Please note this issue tracker is not a help forum. We recommend using StackOverflow or our discord channel for questions.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 12, 2021
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Projects
None yet
Development

No branches or pull requests

2 participants