Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High severity security vulnerabilities introduced by the js-yaml v3.5.3 Tangram fork #781

Open
rokotyan opened this issue Jun 28, 2021 · 1 comment

Comments

@rokotyan
Copy link

TANGRAM VERSION:
Tangram version: 0.21.1
The js-yaml fork used in Tangram has high severity security vulnerabilities according to npm audit. That makes it difficult to use Tangram in any kind of enterprise product. Is it possible to update js-yaml to version 3.13.1 or later?

ENVIRONMENT:
macOS 10.15.7

TO REPRODUCE THE ISSUE, FOLLOW THESE STEPS:
Add Tangram as a dependency to your project. Run npm audit (or yarn audit)

RESULT:

js-yaml  <=3.13.0
Severity: high
Denial of Service - https://npmjs.com/advisories/788
Code Injection - https://npmjs.com/advisories/813

EXPECTED RESULT:
npm audit should not find vulnerabilities related to Tangram.

@cluen
Copy link

cluen commented Feb 14, 2024

Any updates on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants