Skip to content

[rush] @microsoft/rush-lib depends on a version of js-yaml that has a security issue #5843

Description

@kgetz-arista

Today, @microsoft/rush-lib depends on version "~4.1.0" of js-yaml:

https://github.com/microsoft/rushstack/blob/main/libraries/rush-lib/package.json#L71C16-L71C24

This version has a security issue: GHSA-h67p-54hq-rp68

@microsoft/rush-lib needs to be updated to use 4.2.x instead.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Needs triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions