Skip to content

Conversation

@pavelflux
Copy link
Collaborator


labels: mergeable

Fixes: FFL-1644

Motivation and Context

There is a vulnerability in js-yaml package, which is used by eslint and jest in this package.

Description

adding resolution should be enough

upgrade of ESLint is quite a heavy change, and upgrading of jest to lates version does not resolve the issue

How has this been tested?

@pavelflux pavelflux changed the title Pavlo.khrebto/ffl 1644/js yanl vuln fix Pavlo.khrebto/ffl 1644/js yaml vuln fix Jan 12, 2026
@pavelflux pavelflux merged commit 9198d87 into main Jan 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants