Upgrade js-yaml to avoid Denial of Service by Teamop · Pull Request #39 · cloudfoundry-community/node-cfenv

Skip to content

Navigation Menu

Sign in

Appearance settings

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Appearance settings

Merged

pmuellr merged 1 commit intocloudfoundry-community:masterfrom

Teamop:fix-js-yaml

Mar 25, 2019

Merged

Conversation

@Teamop

Copy link Copy Markdown

Contributor

@Teamop Teamop commented

Mar 22, 2019

Based on the npm audit, there is an security issue with js-yaml, so upgrade to the latest version to fix.
And with the latest js-yaml version, all the test cases can still pass.

Copy link Copy Markdown

Member

@pmuellr pmuellr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Thanks for the PR!

@pmuellr pmuellr merged commit 3f19f12 into cloudfoundry-community:master

Mar 25, 2019

@pmuellr

Copy link Copy Markdown

Member

pmuellr commented

Mar 25, 2019

Now available on npm as version 1.2.1 - https://www.npmjs.com/package/cfenv

Thanks again!

Teamop reacted with thumbs up emoji

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

@pmuellr pmuellr pmuellr approved these changes

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@Teamop @pmuellr