Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes prototype pollution issue in webpack loader-utils #1610

Merged
merged 1 commit into from Nov 9, 2022

Conversation

afs
Copy link
Member

@afs afs commented Nov 9, 2022

This PR updates webpack loader-utils to v1.4.1 for the fix
webpack/loader-utils#220
in response to
github/advisory-database#805

This PR is instead of PR#1609 which updates the generated yarn.lock file. This PR updates package.json and then regerates yarn.lock with yarn install. It includes various incremental updates that rerunning yarn install decided to do.


By submitting this pull request, I acknowledge that I am making a contribution to the Apache Software Foundation under the terms and conditions of the Contributor's Agreement.

@afs afs added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Nov 9, 2022
@afs afs merged commit abe778d into apache:main Nov 9, 2022
@afs afs deleted the loader-utils-upgrade branch November 9, 2022 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants