-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical vulnerability issue in dependency loader-utils
version 1.2.3
#73
Comments
Guys, please take a look at the PR #74 and make a new release. |
Ivan-Strahovsky
pushed a commit
to Ivan-Strahovsky/typings-for-css-modules-loader
that referenced
this issue
Nov 11, 2022
…ion with the fix, don't want to upgrade to the latest available version as it two major versions up and I'm not in this repo code and can't guarantee I this update will be smooth.
This seriously needs a fix as this is a critical issue. Please accept the fix and make a new release ASAP! |
As a temporary workaround, you can add this to "overrides": {
"loader-utils": "^1.4.2"
} |
Merged, sorry for the wait. Going to prepare a release shortly |
@Obi-Dann if fixed can we close this issue? |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This library,
typings-for-css-modules-loader
, currently has a dependency onloader-utils
version 1.2.3 specifically, which has a critical-severity vulnerability:Please update the dependency to address this critical vulnerability that is being flagged in Dependabot alerts of projects that depend on typings-for-css-modules-loader
The text was updated successfully, but these errors were encountered: