Surnet/swagger-jsdoc

Vulnerability with dependency yaml@2.0.0-1

ankit201206 opened this issue ยท 6 comments

There is a security vulnerability discovered with a deep-down dependency of yaml@2.0.0-1. It looks like this has been resolved with v2.2.2, so an upgrade of that dependency version to v2.2.2 seems to be in order.

Hi, @ankit201206 thanks

can you send a pr fixing it, please?

There's a PR already from the dependency bot - #360

@daniloab , Hi! Please let us know, what is ETA of new version release with this fix?

@daniloab , Hi! Please let us know, what is ETA of new version release with this fix?

We need a fix in the yaml 2.2.2 dependabot pull request. Can someone fix this for us, please? Or check why the tests are breaking it

Vulnerability is still in there.
Is there going to be a fix soon?

stale commented

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.