You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Security review of our project with a client shows vulnerabilities in yargs-parser, inherited from [email protected] in sitecore-jss-rendering-host@14.
Expected behavior
yargs-parser version in use should be the same peer-dependency as other packages in the jss solution (15.0.1 or other version including the fix), not one of the vulnerable versions.
Description
Security review of our project with a client shows vulnerabilities in yargs-parser, inherited from [email protected] in sitecore-jss-rendering-host@14.
Expected behavior
yargs-parser version in use should be the same peer-dependency as other packages in the jss solution (15.0.1 or other version including the fix), not one of the vulnerable versions.
Steps To Reproduce
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Possible Fix
Package sitecore-jss-rendering-host needs to be updated to 3.11.X which doesn't use the vulnerable dependency.
Your Environment
Screenshots
The text was updated successfully, but these errors were encountered: