dotansimha / dotansimha/graphql-code-generator
Dependabot detects problems with yaml dependency
- Dominant language
- TypeScript
- Stars
- 11.3k
- Forks
- 1.4k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 23
Description
### Which packages are impacted by your issue?
@graphql-codegen/cli
### Describe the bug
A vulnerability was found in the `yaml` dependency and upgrading to `2.2.2` is recommended.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2251
### Your Example Website or App
Unrelated
### Steps to Reproduce the Bug or Issue
1. Run dependabot or any other security checking tool on a repo including `@graphql-codegen/cli`
### Expected behavior
`yaml` to be updated to a more secure version
### Screenshots or Videos
_No response_
### Platform
- OS: [e.g. macOS, Windows, Linux] N/a
- NodeJS: [e.g. 18.5.0] N/a
- `graphql` version: [e.g. 16.3.0] N/a
- `@graphql-codegen/cli` version(s): [e.g. 2.6.2] 3.3.1
### Codegen Config File
_No response_
### Additional context
_No response_
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.