eemeli/yaml is included and is subject to CVE-2023-2251, can you upgrade bable-plugin-macros to remove that venerable dependency

Author: jchambers-lnCreated Dec 17, 2025Updated Dec 17, 2025

The dependency below is reporting CVE-2023-2251 in security scanners, would it be possible to upgrade the version of babel-plugin-macros to a higher version so that it removes the dependency on eemeli/[email protected] (cosmicconfig moves to a different yaml library in newer versions) -- I initially thought this was a false positive in my scanner until I dug deep and realized the older cosmicconfig used that library but changed in newer versions.

[email protected] [email protected] [email protected]

Source: projectstorm/react-diagrams