Security Vulnerability in peer dependancy "yaml" need to update to yaml 2.8.3
还没有人认领这个 Issue。
评估
- 难度
- 1/5
- 预计耗时
- 1 小时以内
- 新手友好度
- 82/100
调研方向
首先定位声明 yaml peer dependency 的 package 元数据。将声明的版本更新为 2.8.3 或更高版本,然后运行项目现有的检查,以确认依赖项更新不会导致安装或测试出错。
由索引模型根据 Issue 内容生成。
描述
This library 'patch-package' is using yaml in its peer dependancies which is having security vulnerability and version of peer dependancy should be upgraded.
"yaml" vulnerability
Affected versions of this package are vulnerable to Uncontrolled Recursion in the compose/resolve phase due to using recursive function calls without a depth bound. An attacker can cause the application to throw a RangeError and potentially terminate the Node.js process by supplying a deeply nested YAML payload that exhausts the call stack.
Solution
Upgrade yaml to version 2.8.3 or higher.
- 主要语言
- TypeScript
- 星标
- 11.2k
- 派生
- 325
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ds300/patch-package 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
ds300/patch-package#615 · 1 条评论 · 4 个 reaction ·
-
难度 2/5 1-3 小时 新手友好度 62/100
ds300/patch-package#216 ·
-
难度 3/5 1-2 天 新手友好度 25/100
ds300/patch-package#611 · 1 条评论 ·
-
难度 4/5 3-5 天 新手友好度 35/100
ds300/patch-package#610 · 4 条评论 · 1 个 reaction ·
-
难度 5/5 一周以上 新手友好度 28/100
ds300/patch-package#609 · 2 条评论 ·
查看 ds300/patch-package 的全部 Issue
相似的 Issue
-
needs:triage
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
ai-discovered
难度 2/5 1-3 小时 新手友好度 83/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
jessepollak/home#1627 ·
维护者通常 1 天内回复
-
agent-canvas bug llm priority:low ready-for-dev
难度 2/5 1-3 小时 新手友好度 82/100
OpenHands/OpenHands#17806 · 3 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 76/100
radius-project/ai-extensions#923 ·
维护者通常 1 天内回复