Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerabilities in packages - js-yaml #104

Open
lukasz-galka opened this issue Jul 5, 2019 · 4 comments
Open

vulnerabilities in packages - js-yaml #104

lukasz-galka opened this issue Jul 5, 2019 · 4 comments
Assignees

Comments

@lukasz-galka
Copy link

npm audit finds vulnerabilities in your packages, could you update optimize-css-assets-webpack-plugin?


                       === npm audit security report ===


                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance


  Moderate        Denial of Service

  Package         js-yaml

  Patched in      >=3.13.0

  Dependency of   cloudinary-video-player [dev]

  Path            cloudinary-video-player > optimize-css-assets-webpack-plugin
                  > cssnano > postcss-svgo > svgo > js-yaml

  More info       https://nodesecurity.io/advisories/788


  High            Code Injection

  Package         js-yaml

  Patched in      >=3.13.1

  Dependency of   cloudinary-video-player [dev]

  Path            cloudinary-video-player > optimize-css-assets-webpack-plugin
                  > cssnano > postcss-svgo > svgo > js-yaml

  More info       https://nodesecurity.io/advisories/813

found 2 vulnerabilities (1 moderate, 1 high) in 9283 scanned packages
  2 vulnerabilities require manual review. See the full report for details.
@idobarnoam idobarnoam self-assigned this Jul 7, 2019
@idobarnoam
Copy link

Thanks for bringing this to our attention, @lukasz-galka
We will take this internally and see how to approach this.

@idobarnoam
Copy link

Thanks for your patience @lukasz-galka.
These are planned to be handled on the next release of the player.

@lukasz-galka
Copy link
Author

@idobarnoam thanks!

@the-J
Copy link

the-J commented Sep 19, 2019

Hey @idobarnoam is there any estimate on when could we expect new release? Thanks in advance.

@roeeba roeeba assigned ghost and unassigned idobarnoam Oct 10, 2019
@ghost ghost assigned e1adn and unassigned ghost Jun 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants