You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@mannyistyping true, I re-updated the yaml dependency manually because the Dependabot PR was rejected in the past because on Node.js compatibility. Now with the project requiring Node >=16 it should not be a problem.
However the release was not done yet, so probably the issue still persists.
Which packages are impacted by your issue?
@graphql-codegen/cli
Describe the bug
A vulnerability was found in the
yaml
dependency and upgrading to2.2.2
is recommended.https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2251
Your Example Website or App
Unrelated
Steps to Reproduce the Bug or Issue
@graphql-codegen/cli
Expected behavior
yaml
to be updated to a more secure versionScreenshots or Videos
No response
Platform
graphql
version: [e.g. 16.3.0] N/a@graphql-codegen/cli
version(s): [e.g. 2.6.2] 3.3.1Codegen Config File
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: