Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dset dependency vulnerability issue #76

Open
megob56 opened this issue Oct 1, 2024 · 1 comment
Open

Dset dependency vulnerability issue #76

megob56 opened this issue Oct 1, 2024 · 1 comment

Comments

@megob56
Copy link

megob56 commented Oct 1, 2024

react-scanner is using dset version 3.1.2 which is causing high severity warnings on npm.

Github advisory board warns of a prototype pollution vulnerability which can be resolved by upgrading dset to version 3.1.4 where a patch has been added to fix this vulnerability.

Can the version of dset in this package please be upgraded to version 3.1.4 to eliminate the vulnerability issue?

@mikbeach
Copy link
Collaborator

mikbeach commented Oct 1, 2024

I've raised a PR to update dset.

#77

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants