boopathi/react-svg-loader

js-yaml advisory

dekaikiwi opened this issue · 6 comments

Is there any plan to update the version of js-yaml at all?

Currently yarn audit yields the following advisory.

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate      │ Denial of Service                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ js-yaml                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=3.13.0                                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ react-svg-loader                                             │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ react-svg-loader > react-svg-core > svgo > js-yaml           │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/788                       │
└───────────────┴──────────────────────────────────────────────────────────────┘

It seems to already be fixed in this commit: e8884d1

Would be ice to have a version out with the fix :)

when will be the next release to fix this issue ?

Adding another request here for a release push!

Would be great if this could be pushed 😄

An additional request for a release push 💃 😄

Published 3.0.0