-
Notifications
You must be signed in to change notification settings - Fork 3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
@babel/traverse security vulnerability #80
Comments
andreyfel
added a commit
to retailnext/ember-bem-helpers
that referenced
this issue
Dec 13, 2023
https://github.com/retailnext/ember-bem-helpers/security/dependabot/26 ember-cli was updated to v5.5.0 and it got a new dependency from ember-template-tag which has dependencies locked at certain (vulnerable) versions: patricklx/ember-template-tag#80 Use pnpm overrides to fix that.
andreyfel
added a commit
to retailnext/ember-bem-helpers
that referenced
this issue
Dec 13, 2023
https://github.com/retailnext/ember-bem-helpers/security/dependabot/26 ember-cli was updated to v5.5.0 and it got a new dependency from ember-template-tag which has dependencies locked at certain (vulnerable) versions: patricklx/ember-template-tag#80 Use pnpm overrides to fix that.
@patricklx Any ETA on this? Thank you |
@patricklx would be great to update this dependency to alllow range |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
@babel/traverse below 7.23.2 is vulnerable.
GHSA-67hx-6x53-jw92
All the apps updated to ember-cli 5.5.0 became vulnerable.
This package should allow ranges in the dependencies instead of locked versions.
The text was updated successfully, but these errors were encountered: