Open
Description
Vulnerabilities in Dependencies in Yarn 1.22.19 to 1.22.22
Description
Yarn versions 1.22.19 to 1.22.22 have security vulnerabilities in its dependencies, specifically braces
. The affected and patched versions are as follows:
1. Braces
- Affected versions:
<3.0.0
- Patched versions:
3.0.3
GitHub Advisory Links
- braces: GHSA-grv7-fg5c-xmjg
Request
Could these dependencies be updated to the patched versions in Yarn 1.22.19 to 1.22.22 ? Thank you.
Metadata
Metadata
Assignees
Labels
No labels