-
Notifications
You must be signed in to change notification settings - Fork 22
update js-yaml to 4.1.x #56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
resolves #54 This allows js-yaml 4.1.1 to be used, to avoid [CVE-2025-64718][]. [CVE-2025-64718]: https://www.cve.org/CVERecord?id=CVE-2025-64718
| "js-yaml": "4.1.x", | ||
| "ports": "1.1.x", | ||
| "underscore": "1.12.x" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would be great to have more flexibility:
| "js-yaml": "4.1.x", | |
| "ports": "1.1.x", | |
| "underscore": "1.12.x" | |
| "js-yaml": "^4.1.1", | |
| "ports": "^1.1.0", | |
| "underscore": "^1.13.7" |
ports hasn't been updated in 12 years, underscore@1.12.1 is 5 years old
At least for underscore something can be done, 1.13.7 is 16 months old, in 2 months it will also start triggering security warnings, but at least it will be easier to justify them.
|
Can this please be merged ASAP? We need this fix to address that CVE. Thanks! |
|
I'll eventually get to this, but it's on my back burner - I have no skin in this game. We'll have to find a new maintainer if there end up being frequent dependency updates ... because I have no time to deal with this. Presumably anyone willing to help maintain this would need to become a member of this org. |
|
@pmuellr Hello again! When can we expect this PR to be merged and this vulnerability fix to be published? Thanks! |
resolves #54
This allows js-yaml 4.1.1 to be used, to avoid CVE-2025-64718.