Skip to content

Conversation

@Zearin
Copy link

@Zearin Zearin commented Apr 13, 2024

The latest version of js-yaml uses the “safe” function variants by default now.

The migration guide for v3 to v4 is here, if you want to check for any edge cases.

The latest version of `js-yaml` uses the “safe” function variants by default now.

The [migration guide for v3 to v4 is here](https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md), if you want to check for any edge cases.
@Eric-Arellano
Copy link

Hey @jonschlinkert, any chance you would be willing to please merge this and deploy a new release? js-yaml has a CVE that was only patched in v4 and not v3. https://www.mend.io/vulnerability-database/CVE-2025-64718

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants