Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot detects problems with yaml dependency #9341

Open
ruben-treams opened this issue Apr 25, 2023 · 3 comments
Open

Dependabot detects problems with yaml dependency #9341

ruben-treams opened this issue Apr 25, 2023 · 3 comments

Comments

@ruben-treams
Copy link

Which packages are impacted by your issue?

@graphql-codegen/cli

Describe the bug

A vulnerability was found in the yaml dependency and upgrading to 2.2.2 is recommended.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2251

Your Example Website or App

Unrelated

Steps to Reproduce the Bug or Issue

  1. Run dependabot or any other security checking tool on a repo including @graphql-codegen/cli

Expected behavior

yaml to be updated to a more secure version

Screenshots or Videos

No response

Platform

  • OS: [e.g. macOS, Windows, Linux] N/a
  • NodeJS: [e.g. 18.5.0] N/a
  • graphql version: [e.g. 16.3.0] N/a
  • @graphql-codegen/cli version(s): [e.g. 2.6.2] 3.3.1

Codegen Config File

No response

Additional context

No response

@DerTimonius
Copy link

This issue still persists.

@cichelero cichelero mentioned this issue Jun 26, 2023
14 tasks
@mannyistyping
Copy link

It looks like yaml is now at 2.3.1

As mentioned by @cichelero in #9513

@ruben-treams & @DerTimonius would you both agree?
If so, would it make sense to close this issue?

@cichelero
Copy link
Contributor

@mannyistyping true, I re-updated the yaml dependency manually because the Dependabot PR was rejected in the past because on Node.js compatibility. Now with the project requiring Node >=16 it should not be a problem.

However the release was not done yet, so probably the issue still persists.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants