-
-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Closed
Labels
Description
Is there an existing issue for this?
- I have checked for existing issues https://github.com/getsentry/sentry-javascript/issues
- I have reviewed the documentation https://docs.sentry.io/
- I am using the latest SDK release https://github.com/getsentry/sentry-javascript/releases
How do you use Sentry?
Sentry Saas (sentry.io)
Which SDK are you using?
@sentry/nextjs
SDK Version
8.31.0
Framework Version
No response
Link to Sentry event
No response
Reproduction Example/SDK Setup
When I run npm audit
the suggestion is to download Sentry.
rollup <3.29.5
Severity: high
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS - https://github.com/advisories/GHSA-gcx4-mw62-g8wm
fix available via `npm audit fix --force`
Will install @sentry/nextjs@7.11.1, which is a breaking change
node_modules/rollup
@sentry/nextjs >=7.12.0
Depends on vulnerable versions of rollup
node_modules/@sentry/nextjs
Steps to Reproduce
npm i @sentry/nextjs@latest
npm audit
Expected Result
No security issues
Actual Result
joms, fipp, jonas-jonas and 4esnog
Metadata
Metadata
Assignees
Labels
Projects
Status
Waiting for: Product Owner