Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump sass-graph from 4.0.0 to 4.0.1 #3294

Closed
wants to merge 1 commit into from
Closed

Conversation

alexmk92
Copy link

@alexmk92 alexmk92 commented Sep 2, 2022

I received this warning in one of my projects today. It appears sass-graph bumped the conflicting dependency and released 4.0.1 as a new minor version to rectify it.

image

Regular expression denial of service in scss-tokenizer sass#2
@abelmark
Copy link

abelmark commented Sep 2, 2022

Can we make this a priority? This seems to be affecting a lot of users.

@alexmk92
Copy link
Author

alexmk92 commented Sep 2, 2022

Apologies, closing as #3292 already exists.

@alexmk92 alexmk92 closed this Sep 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants