Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Please update json-schema-ref-parser to 7.0.0 to fix security vulnerabilities #1478

Closed
bogn83 opened this issue Dec 7, 2020 · 2 comments

Comments

@bogn83
Copy link

bogn83 commented Dec 7, 2020

Both of these are fixed starting with json-schema-ref-parser 7.0.0

+----------------------+---------------------+----------+-------------------+---------------+--------------------------------+-------------------------------------------+
|       LIBRARY        |  VULNERABILITY ID   | SEVERITY | INSTALLED VERSION | FIXED VERSION |             TITLE              |                    URL                    |
+----------------------+---------------------+----------+-------------------+---------------+--------------------------------+-------------------------------------------+
| js-yaml              | GHSA-8j8c-7jfh-h6hx | HIGH     | 3.12.2            | 3.13.1        | Code Injection in js-yaml      | github.com/advisories/GHSA-8j8c-7jfh-h6hx |
+                      +                     +          +-------------------+               +                                +                                           +
|                      |                     |          | 3.7.0             |               |                                |                                           |
+                      +---------------------+----------+-------------------+---------------+--------------------------------+-------------------------------------------+
|                      | GHSA-2pr6-76vf-7546 | MEDIUM   | 3.12.2            | 3.13.0        | Denial of Service in js-yaml   | github.com/advisories/GHSA-2pr6-76vf-7546 |
+                      +                     +          +-------------------+               +                                +                                           +
|                      |                     |          | 3.7.0             |               |                                |                                           |
+----------------------+---------------------+----------+-------------------+---------------+--------------------------------+-----------------------------------------
@RomanHotsiy
Copy link
Member

we are removing it soon: #1500

@andriyl
Copy link
Contributor

andriyl commented Apr 9, 2021

@bogn83 completed, #1500, v2.0.0-rc.51

@andriyl andriyl closed this as completed Apr 9, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants