JS-Yaml Denial of Service in v3.12 #3842
Labels
area: node.js
command-line-or-Node.js-specific
area: security
involving vulnerabilities
semver-patch
implementation requires increase of "patch" version number; "bug fixes"
type: bug
a defect, confirmed by a maintainer
Milestone
Just got a vulnerability message from npm on one of my repos using Mocha. Looks like the dep
js-yaml
needs to be updated from 3.12 to >=3.13Link: https://npmjs.com/advisories/788
The text was updated successfully, but these errors were encountered: