Hello Team,
We noticed that the dependency vulnerabilities reported in the project include issues related to ts-deepmerge and js-yaml.
The ts-deepmerge vulnerability appears to have already been addressed, and the corresponding PR has been merged.
The js-yaml vulnerability, however, does not appear to be fixed yet.
Could you please provide an estimated timeline for the next release that will include:
The merged ts-deepmerge fix.
A fix for the js-yaml vulnerability (if one is planned or currently in progress).
We would appreciate any update on the release schedule, as these vulnerabilities are impacting our dependency compliance requirements.
Thank you for your support.
Hello Team,
We noticed that the dependency vulnerabilities reported in the project include issues related to ts-deepmerge and js-yaml.
The ts-deepmerge vulnerability appears to have already been addressed, and the corresponding PR has been merged.
The js-yaml vulnerability, however, does not appear to be fixed yet.
Could you please provide an estimated timeline for the next release that will include:
The merged ts-deepmerge fix.
A fix for the js-yaml vulnerability (if one is planned or currently in progress).
We would appreciate any update on the release schedule, as these vulnerabilities are impacting our dependency compliance requirements.
Thank you for your support.