Skip to content

Please update yarn to at least 1.22.0 (CVE-2020-8131) #1237

Description

@sseide

Current version of yarn used on all (?) images has a vulnerablilty which may be exploited depending on how your images are used or what software is installed on top of it.

https://nvd.nist.gov/vuln/detail/CVE-2020-8131 - Rating of 7.5 (HIGH)

Please update all images to the bugfixed version as some automated security scanners start to pick up this vulnerability in docker images (e.g. Anchore).

I have looked if there is a helper script to update all instances easily without missing on but there seems nothing like it. is there another preferred way or search-replace? I can create a PR than.

Thanks

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions