Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update core-js due security issue #394

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

phyr0s
Copy link

@phyr0s phyr0s commented Mar 1, 2023

No description provided.

@phyr0s phyr0s requested a review from a team as a code owner March 1, 2023 14:51
@compulim
Copy link
Collaborator

It's good to bump deps.

Instead of hand-modifying package.json, please run npm install core-js@latest and update CHANGELOG.md.

@compulim
Copy link
Collaborator

BTW, I ran npm audit and it didn't report anything related to core-js.

@dmunozse
Copy link

dmunozse commented Apr 10, 2023

Hi @compulim!

Version update is due to a vulnerability found while running Sonar:

https://ossindex.sonatype.org/vulnerability/sonatype-2023-0962

This vulnerability is fixed by upgrading the core-js package version to at least version 3.28.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants