Fix dependency on js-yaml version that has a code injection vulnerability
envgap__cssnano__cssnano-729
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
8d4610a6391ddab29bcb08ef0522d0b7ce2d6582- Manifest
packages/postcss-svgo/package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
cssnano/cssnano #729 · read the original issue
Hi there, Thanks for making cssnano! you have a dependency on `svgo` which in turn has a dependency on `js-yaml`. Please see this report of a `High` severity vulnerability in this module. https://www.npmjs.com/advisories/813
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]