Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[NodeToolV0] Update dependencies #14620

Merged
merged 3 commits into from
Mar 23, 2021

Conversation

max-zaytsev
Copy link

@max-zaytsev max-zaytsev commented Mar 18, 2021

Task name: NodeToolV0

Description: Update dependencies

In order to fix this vulnerability js-yaml version was upgraded in azure-pipelines-tasks-utility-common version 3.0.2

Versions of js-yaml prior to 3.13.1 are vulnerable to Code Injection. The load() function may execute arbitrary code injected through a malicious YAML file.

Documentation changes required: N

Added unit tests: N

Attached related issue: N

Checklist:

  • Task version was bumped - please check instruction how to do it
  • Checked that applied changes work as expected

@EzzhevNikita EzzhevNikita requested a review from a team March 19, 2021 14:51
@max-zaytsev max-zaytsev merged commit 2514183 into master Mar 23, 2021
@max-zaytsev max-zaytsev deleted the users/max-zaytsev/nodetool-oss-js-yaml branch March 23, 2021 07:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants