Skip to content

js-yaml (prior to 3.13.0) security vulnerability #3664

Closed
@yuanstanley

Description

@yuanstanley

Looks like js-yaml 3.12.1, which my security scan says Plotly depends on, has a Denial of Service security vulnerability. A yarn why seems to indicate that it's coming from plotly.js -> mapbox-gl -> gray-matter.

Info on the js-yaml security vulnerability - https://www.npmjs.com/advisories/788

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions