Skip to content
This repository has been archived by the owner on Jul 24, 2024. It is now read-only.

Bump sass-graph from 4.0.0 to 4.0.1 #3294

Closed
wants to merge 1 commit into from
Closed

Conversation

alexmk92
Copy link

@alexmk92 alexmk92 commented Sep 2, 2022

I received this warning in one of my projects today. It appears sass-graph bumped the conflicting dependency and released 4.0.1 as a new minor version to rectify it.

image

Regular expression denial of service in scss-tokenizer sass#2
@abelmark
Copy link

abelmark commented Sep 2, 2022

Can we make this a priority? This seems to be affecting a lot of users.

@alexmk92
Copy link
Author

alexmk92 commented Sep 2, 2022

Apologies, closing as #3292 already exists.

@alexmk92 alexmk92 closed this Sep 2, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants