Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High vulnerabilities in teamsfx-cli 2.0.1 regarding the yaml dependency #9819

Closed
brooklynb7 opened this issue Sep 1, 2023 · 2 comments
Closed
Assignees
Labels

Comments

@brooklynb7
Copy link

brooklynb7 commented Sep 1, 2023

Describe the bug
In teamsfx-cli version 2.0.1, there are 4 high vulnerabilities derived from the dependency of yaml.

To Reproduce

  • use "@microsoft/teamsfx-cli": "2.0.1" in dependencies of package.json
  • run npm audit

Expected behavior
The high vulnerabilities should be avoided.

Screenshots
image

VS Code Extension Information (please complete the following information):
N/A

CLI Information (please complete the following information):

  • OS: Win 10
  • Version 2.0.1

Additional context
N/A

@microsoft-github-policy-service
Copy link
Contributor

Thank you for contacting us! Any issue or feedback from you is quite important to us. We will do our best to fully respond to your issue as soon as possible. Sometimes additional investigations may be needed, we will usually get back to you within 2 days by adding comments to this issue. Please stay tuned.

@brooklynb7 brooklynb7 changed the title 4 vulnerabilities in teamsfx-cli regarding the yaml dependency High vulnerabilities in teamsfx-cli 2.0.1 regarding the yaml dependency Sep 1, 2023
@adashen adashen added investigating TA:E2E Team Area: E2E labels Sep 4, 2023
@jayzhang
Copy link
Member

@brooklynb7 Sorry for delay for the response, the issues are fixed in the latest CLI (@microsoft/[email protected]).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants