Replies: 1 comment
-
I have figured out how to use "overrides" within the package.json |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The latest OWASP scans and NPM audits are identifying a security vulnerability in the Json5 <= v2.2.1 package which is used by the @babel/core v7.16.0.
@babel/core v7.21.8 has update its dependency to Json5 v2.2.2 which contains a patch.
Is there any chance react-scripts can be updated to use the newer babel/core?
Since react-scripts is added as an application dependency and not a devDependency, it is picked up by the scans and thus it would be nice if we can update it to clean up the scan results.
Beta Was this translation helpful? Give feedback.
All reactions