-
Notifications
You must be signed in to change notification settings - Fork 111
Open
@helinsuezer
Description
Hello!
There is a vulnerability issue with one of the dependencies. Would you be able to fix it? Thanks for maintaining this package.
Vulnerability: js-yaml 4.1.0 has a prototype pollution vulnerability (BDSA-2025-27523) that allows attackers to modify object prototypes via crafted YAML with proto nodes.
Current version: 4.1.0
Fixed version: 4.1.1+
Metadata
Metadata
Assignees
Labels
No labels