You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 19, 2022. It is now read-only.
Our repo Reactochart uses measure-text and we found that it may have a potential security vulnerability. Tracing our package-lock.json it maps to url-loader v0.5.9 which uses mime v1.3.6 which I believe has the vulnerability.
Hey @tptee . We're going to import measure-text's source code into our repo for now. Will try to get around to a PR but unfortunately don't have the bandwidth right now to update url-loader and fix any breaking dependencies upon upgrade. This also solves issue spotify/reactochart#123 for us.
Hello!
Our repo Reactochart uses
measure-text
and we found that it may have a potential security vulnerability. Tracing our package-lock.json it maps tourl-loader
v0.5.9 which usesmime
v1.3.6 which I believe has the vulnerability.It's fixed in later versions broofa/mime#167.
Let me know if this is something I can help with!
The text was updated successfully, but these errors were encountered: