Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

just-scripts pulls in dependencies which create component governance warnings #480

Closed
NickGerleman opened this issue Oct 20, 2020 · 1 comment

Comments

@NickGerleman
Copy link

just-scripts-utils and just-task-logger depend on yargs@^12.0.5. This brings in [email protected], which is vulnerable to CVE-2020-7608 and creates a component governance warning.

Relates to microsoft/react-native-windows#6270

@christiango
Copy link
Member

Duplicate of #469

@christiango christiango marked this as a duplicate of #469 Oct 22, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants