[0.80] Bump screenshot-desktop from 1.15.1 to 1.15.2 for component governance #15198
+3
−3
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Upgraded the following packages
screenshot-desktop from 1.15.1 to 1.15.2
Type of Change
Why
When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization.The issue has been patched in version 1.15.2.All users are strongly recommended to upgrade to 1.15.2 or later
Resolves #15187
What
Updated the yarn.lock to point to the new versions.
Steps to upgrade:
Delete the older version from yarn.lock file
Execute yarn command so it can fetch the new versions.
Screenshots
Changelog
Should this change be included in the release notes: no_
Microsoft Reviewers: Open in CodeFlow
Microsoft Reviewers: Open in CodeFlow