Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update loader-utils on v3 branch to fix audit vulnerability. #1532

Closed
dscalzi opened this issue May 10, 2020 · 6 comments · Fixed by #1595
Closed

Update loader-utils on v3 branch to fix audit vulnerability. #1532

dscalzi opened this issue May 10, 2020 · 6 comments · Fixed by #1595

Comments

@dscalzi
Copy link

dscalzi commented May 10, 2020

npm audit is unable to fix a a vulnerability because there is no version range on the loader-utils dependency (https://github.com/webpack/webpack-cli/blob/master/package.json#L123).

image

Updating this dependency and releasing v3.3.12 will fix the issue. (https://www.npmjs.com/advisories/1179/versions)

@anshumanv
Copy link
Member

Thanks for reporting.

Will submit a fix 👍

@dscalzi
Copy link
Author

dscalzi commented May 27, 2020

Any update?

@anshumanv
Copy link
Member

Hi, occupied with other tasks, can your PR or anyone from @webpack/cli-team would like to pick this up?

@jamesgeorge007 jamesgeorge007 linked a pull request May 28, 2020 that will close this issue
@jamesgeorge007
Copy link
Member

jamesgeorge007 commented May 31, 2020

@evilebottnawi please make a patch release.

@alexander-akait
Copy link
Member

@jamesgeorge007 in TODO

@dscalzi
Copy link
Author

dscalzi commented Jun 11, 2020

Thanks, fixed

@dscalzi dscalzi closed this as completed Jun 11, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants