Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Npm audit js-yaml HIgh vulnerability #8338

Closed
ghost opened this issue Apr 17, 2019 · 4 comments
Closed

Npm audit js-yaml HIgh vulnerability #8338

ghost opened this issue Apr 17, 2019 · 4 comments

Comments

@ghost
Copy link

ghost commented Apr 17, 2019

High Code Injection
Package js-yaml
Dependency of jest
Path jest > jest-cli > @jest/core > @jest/reporters > istanbul-api > js-yaml
More info https://npmjs.com/advisories/813
@SimenB
Copy link
Member

SimenB commented Apr 17, 2019

Report it to istanbul, this is transitive for jest (but note that istanbul-api is gonna be deprecated (istanbuljs/istanbuljs#321))

@SimenB SimenB closed this as completed Apr 17, 2019
@coreyfarrell
Copy link
Contributor

Also note that istanbul-api depends on js-yaml ^3.13.0 which allows the non-vulnerable version to be installed so the issue is likely that your package-lock.json or yarn.lock needs to be regenerated.

@ghost
Copy link
Author

ghost commented Apr 23, 2019

Okay, thank you.

@github-actions
Copy link

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Please note this issue tracker is not a help forum. We recommend using StackOverflow or our discord channel for questions.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 12, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants