Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

js yaml vulnerability #388

Closed
cdmo opened this issue Jul 2, 2019 · 1 comment
Closed

js yaml vulnerability #388

cdmo opened this issue Jul 2, 2019 · 1 comment
Assignees

Comments

@cdmo
Copy link
Contributor

cdmo commented Jul 2, 2019

js yaml has a vulnerability, it is a dependency of webpacker.

Webpacker does not currently have a tagged 3.x release of a fix for this. Their most recent is 3.6.0 which does not use the required version of js yaml (3.13.1)

nodeca/js-yaml#480
nodeca/js-yaml#475

@cdmo cdmo added this to the 0.2.x Pre-Release 2 milestone Jul 2, 2019
@cdmo
Copy link
Contributor Author

cdmo commented Jul 2, 2019

4.x version does have a fix btw https://github.com/rails/webpacker/blob/v4.0.7/package.json

@cdmo cdmo self-assigned this Jul 3, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants