From 9d4ce5e2895365c943d2bdf7e7c8ac1be3ec51a3 Mon Sep 17 00:00:00 2001 From: Vitaly Puzrin Date: Wed, 20 Mar 2019 22:13:29 +0300 Subject: [PATCH] 3.13.0 released --- CHANGELOG.md | 7 +++++++ package.json | 2 +- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ed0d7263..42c0acdb 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,10 @@ +3.13.0 / 2019-03-20 +------------------- + +- Security fix: `safeLoad()` can hang when arrays with nested refs + used as key. Now throws exception for nested arrays. #475. + + 3.12.2 / 2019-02-26 ------------------- diff --git a/package.json b/package.json index 2daceae8..9f605d3b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "js-yaml", - "version": "3.12.2", + "version": "3.13.0", "description": "YAML 1.2 parser and serializer", "keywords": [ "yaml",