There is CVE-2022-25883 against semver which this package indirectly depends on via @babel/core.
#11
Open
opened 1 year ago by bbuck
·
0 comments
Loading…
Reference in New Issue
There is no content yet.
Delete Branch '%!s(<nil>)'
Deleting a branch is permanent. It CANNOT be undone. Continue?
Recently had our security scanner flag our container due to the version of
semver
being used by@babel/core
as part of this package.https://nvd.nist.gov/vuln/detail/CVE-2022-25883
It seems like a non-issue, but since there have no updates in 2 years it might be benenficial to update some dependency versions if they're simple.