Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in yargs-parser used by sitecore-jss-rendering-host #458

Closed
girlcheese opened this issue Sep 25, 2020 · 1 comment
Closed

Comments

@girlcheese
Copy link

Description

Security review of our project with a client shows vulnerabilities in yargs-parser, inherited from [email protected] in sitecore-jss-rendering-host@14.

Expected behavior

yargs-parser version in use should be the same peer-dependency as other packages in the jss solution (15.0.1 or other version including the fix), not one of the vulnerable versions.

Steps To Reproduce

https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381

Possible Fix

Package sitecore-jss-rendering-host needs to be updated to 3.11.X which doesn't use the vulnerable dependency.

Your Environment

  • Sitecore Version: 9.3
  • JSS Version: 14
  • Browser Name and version: All
  • Operating System and version : n/a
  • Link to your project : private

Screenshots

Screenshot 2020-09-25 at 10 21 46

@sc-illiakovalenko
Copy link
Contributor

@girlcheese Fixed in #464 here. Will be released in JSS 15

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants