jaredpalmer / cypress-image-snapshot

Catch visual regressions in Cypress
MIT License
882 stars 160 forks source link

Critical Security vulnerability CVE-2022-22912 in latest version 4.0.1 due to plist@3.0.4 #249

Open maxprog opened 2 years ago

maxprog commented 2 years ago

Problem with reported Security vulnerability based on CVE-2022-22912. You can check by execute command npm audit report. Problem due to used plist@3.0.4. (more description on https://github.com/advisories/GHSA-4cpg-3vgw-4877). Problem is also reported by trivy scanner for docker images. Is it possible to fix it ASAP? v1