jm-david / emoji-mart-vue

One component to pick them all 👊🏼
https://jm-david.github.io/emoji-mart-vue
BSD 3-Clause "New" or "Revised" License
603 stars 82 forks source link

Code Injection vulnerability in js-yaml dependency #60

Closed LeonAlvarez closed 7 months ago

LeonAlvarez commented 5 years ago

Hi currently package relies on a vulnerable version of js-yaml

dependency path: vue-loader > postcss-load-config > postcss-load-options > cosmiconfig > js-yaml more info : https://npmjs.com/advisories/813
Can be fixed updating the vue-loader dependency wich is outdated.