cucumber / cucumber-js

Cucumber for JavaScript
https://cucumber.io
MIT License
5.04k stars 1.09k forks source link

Update yaml to v2.2.2 to remedy CVE-2023-2251 #2281

Closed aukevanleeuwen closed 1 year ago

aukevanleeuwen commented 1 year ago

More information:

Fixes #2280

🤔 What's changed?

Updated yaml depenency to v2.2.2.

⚡️ What's your motivation?

Fixes vulnerability:

🏷️ What kind of change is this?

♻️ Anything particular you want feedback on?

No.

📋 Checklist:

coveralls commented 1 year ago

Coverage Status

Coverage: 98.489%. Remained the same when pulling 536b75f2b80d436f7c8caec9d7a533d733aea2f8 on aukevanleeuwen:fix-2280-cve-on-yaml into c32b21ea897117177eaf539d4941f4f48618b8f2 on cucumber:main.

aslakhellesoy commented 1 year ago

Hi @aukevanleeuwen,

Thanks for your making your first contribution to Cucumber, and welcome to the Cucumber committers team! You can now push directly to this repo and all other repos under the cucumber organization! 🍾

In return for this generous offer we hope you will:

On behalf of the Cucumber core team, Aslak Hellesøy Creator of Cucumber