[Snyk] Fix for 1 vulnerabilities - #191
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-18593780
|
This upgrade includes a medium-risk change for grunt 1.4.1 → 1.6.3 (Medium Risk) This is a minor version upgrade for the Grunt task runner. The most significant change is introduced in version 1.6.0.
Recommendation: Verify that your CI/CD and local development environments are running Node.js version 16 or higher before merging this upgrade. js-yaml 3.14.1 → 3.15.1 (Low Risk) This is a minor version upgrade that includes security and bug fixes. There are no documented breaking API changes in this range. The upgrade addresses vulnerabilities related to inefficient complexity and potential prototype pollution. Source: grunt changelog, js-yaml changelog
|
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-JSYAML-18593780
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.