postcss / postcss-load-config

Autoload Config for PostCSS
MIT License
638 stars 71 forks source link

Release new version with the patched yaml version that fixes a vulnerability #250

Closed kevinlin505 closed 11 months ago

kevinlin505 commented 11 months ago

I see that there are already updates to the YAML dependency recently but the current release version 4.0.1 has an outdated YAMl version of 2.1.1 that has a vulnerability. Any chance, the team will release a new version soon that patches this?

Details

Error (Logs|Stacks)

Reproduction (Code)

$ git clone https://github.com/<user>/<sample>

Environment

OS node npm/yarn package
[name][version] [version] [version] [version]