Skip to content

Conversation

@ceciliaavila
Copy link
Collaborator

#minor

Description

This PR updates the glob and js-yaml dependencies to safe versions.

Specific Changes

  • Updated glob package to version >= 10.5.0 to fix Command injection via -c/--cmd executes matches with shell:true issue.
  • Updated js-yaml package to version 4.1.1 and 3.14.2 to avoid prototype pollution in merge issue.

Testing

The image shows the audit command, indicating that there are no high or moderate alerts present.
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants