Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE because of dependency on yaml@2.2.1 #2280

Closed
aukevanleeuwen opened this issue Apr 26, 2023 · 2 comments Β· Fixed by #2281
Closed

CVE because of dependency on yaml@2.2.1 #2280

aukevanleeuwen opened this issue Apr 26, 2023 · 2 comments Β· Fixed by #2281

Comments

@aukevanleeuwen
Copy link
Member

πŸ€” What's the problem you've observed?

I was alerted by dependabot of a vulnerability because of a transitive dependency on yaml@2.2.1 (via @cucumber/cucumber-js).

✨ Do you have a proposal for making it better?

Update to yaml@2.2.2.

πŸ“š Any additional context?

@bchew
Copy link

bchew commented May 1, 2023

@davidjgoss is there a plan for a release to npm with this fix soon? Thanks

@davidjgoss
Copy link
Contributor

Released in https://github.com/cucumber/cucumber-js/releases/tag/v9.1.1 - sorry for the delay.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants