mirror of
https://github.com/ckelsoe/obsidian-rss-importer.git
synced 2026-07-22 07:48:56 +00:00
A newly disclosed moderate DoS in js-yaml (<= 4.1.1) is flagged by OSV-Scanner against js-yaml@3.14.2, a deep transitive dev dependency from the test-coverage toolchain (ts-jest -> istanbul -> load-nyc-config -> js-yaml). It is never in the shipped main.js and only parses our own trusted coverage config. The patch is js-yaml 4.2.0, but load-nyc-config needs the removed 3.x safeLoad API, so no non-breaking override exists. Document the acceptance in osv-scanner.toml and point the scanner at it, rather than dropping the severity gate. |
||
|---|---|---|
| .. | ||
| ISSUE_TEMPLATE | ||
| workflows | ||