Skip to content

[rush] @microsoft/rush-lib depends on a version of js-yaml that has a security issue #5843

Description

@kgetz-arista

Today, @microsoft/rush-lib depends on version "~4.1.0" of js-yaml:

https://github.com/microsoft/rushstack/blob/main/libraries/rush-lib/package.json#L71C16-L71C24

This version has a security issue: GHSA-h67p-54hq-rp68

@microsoft/rush-lib needs to be updated to use 4.2.x instead.

Metadata

Metadata

Labels

effort: easyProbably a quick fix. Want to contribute? :-)help wantedIf you're looking to contribute, this issue is a good place to start!

Type

No type
No fields configured for issues without a type.

Projects

Status
Needs triage

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions