┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ js-yaml has prototype pollution in merge (<<) │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ js-yaml │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=4.0.0 <4.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=4.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ packages__hexo-next>@next-theme/utils>js-yaml │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-mh29-5h37-fv8m │
└─────────────────────┴────────────────────────────────────────────────────────┘
In main branch, js-yaml is replaced by yaml (but still a vulnerable version), when can a fresh new version being published? @stevenjoezhang
In main branch, js-yaml is replaced by yaml (but still a vulnerable version), when can a fresh new version being published? @stevenjoezhang