-
-
Notifications
You must be signed in to change notification settings - Fork 405
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependency on vulnerable version of vue-template-compiler #4610
Comments
The CVE indicates its fixed in |
Any update on this issue? |
I have the same problem. Any solution? |
This is ridiculous. What's the point of keeping a dep for an EOL framework? Just let those guy make a parallel project for vue2 and terminate its support on this. (Also, no offense, but I see not only they can't make a public release but they don't even know the difference between a major and a patch). |
Please update vue-tsc to 2.0.29. |
Vue - Official extension or vue-tsc version
vue-tsc
VSCode version
1.91.1
Vue version
2.7
TypeScript version
5.4.2
System Info
Steps to reproduce
Run npm audit on a project with vue-tsc dependency
What is expected?
It should not contain any vulnerability alerts
What is actually happening?
Link to minimal reproduction
No response
Any additional comments?
client-side Cross-Site Scripting (XSS) on vue-template-compiler - GHSA-g3ch-rx76-35fx
The text was updated successfully, but these errors were encountered: