Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Security Vulnerability in peer dependancy "yaml" need to update to yaml 2.8.3

未关闭 适合新手
#617 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
1/5
预计耗时
1 小时以内
新手友好度
82/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
node.js, yaml
领域
security, tooling

调研方向

首先定位声明 yaml peer dependency 的 package 元数据。将声明的版本更新为 2.8.3 或更高版本,然后运行项目现有的检查,以确认依赖项更新不会导致安装或测试出错。

由索引模型根据 Issue 内容生成。

描述

This library 'patch-package' is using yaml in its peer dependancies which is having security vulnerability and version of peer dependancy should be upgraded.

"yaml" vulnerability
Affected versions of this package are vulnerable to Uncontrolled Recursion in the compose/resolve phase due to using recursive function calls without a depth bound. An attacker can cause the application to throw a RangeError and potentially terminate the Node.js process by supplying a deeply nested YAML payload that exhausts the call stack.

Solution
Upgrade yaml to version 2.8.3 or higher.

主要语言
TypeScript
星标
11.2k
派生
325
PR 合并指标
30 天内没有已合并 PR

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

ds300/patch-package 的其他 Issue

查看 ds300/patch-package 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。