-
-
Notifications
You must be signed in to change notification settings - Fork 27.2k
Closed
Description
Right now, react-scripts relies on terser-webpack-plugin, which in turn relies on serialize-javascript. It will need a bump once released. This is causing GitHub to display security alerts on a lot of react repos. I am working to collaborate a fix downstream at terser-webpack-plugin, just opening this issue for meta.
NOTE: This WILL MOST LIKELY NOT HARM YOUR APP. The library is only used at build time.
dillontsmith, akilman, petetnt, shankarps, konekoya and 3 more