Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities with semver and ssri dependencies #9112

Open
ayoubhessoune opened this issue Nov 1, 2024 · 0 comments
Open

Vulnerabilities with semver and ssri dependencies #9112

ayoubhessoune opened this issue Nov 1, 2024 · 0 comments

Comments

@ayoubhessoune
Copy link

ayoubhessoune commented Nov 1, 2024

Vulnerabilities in Dependencies in Yarn 1.22.19

Description

Yarn version 1.22.19 has security vulnerabilities in its dependencies, specifically semver and ssri. The affected and patched versions are as follows:

1. semver

  • Affected versions:
    • >= 7.0.0, < 7.5.2
    • >= 6.0.0, < 6.3.1
    • < 5.7.2
  • Patched versions:
    • 7.5.2
    • 6.3.1
    • 5.7.2

2. ssri

  • Affected versions:
    • >= 5.2.2, < 6.0.2
    • >= 7.0.0, < 7.1.1
    • = 8.0.0
  • Patched versions:
    • 6.0.2
    • 7.1.1
    • 8.0.1

GitHub Advisory Links

Request

Could these dependencies be updated to the patched versions in Yarn 1.22.19 ? Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant