Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability on react-scripts 4.0.3 #10782

Closed
BiancaArtola opened this issue Apr 5, 2021 · 3 comments
Closed

Vulnerability on react-scripts 4.0.3 #10782

BiancaArtola opened this issue Apr 5, 2021 · 3 comments

Comments

@BiancaArtola
Copy link

I am using react-scripts 4.0.3 on my project and the dependabot of GitHub found the following vuln:

Dependabot cannot update is-svg to a non-vulnerable version
The latest possible version that can be installed is 3.0.0 because of the following conflicting dependency:

react-scripts@4.0.3 requires is-svg@^3.0.0 via a transitive dependency on postcss-svgo@4.0.2
The earliest fixed version is 4.2.2.

View logs or learn more about troubleshooting Dependabot errors.

Are you going to fix that?

@matteofigus
Copy link

Duplicate of #10762

@cmacdonnacha
Copy link

Hey, any idea when this will be addressed?

@gaearon
Copy link
Contributor

gaearon commented Jul 7, 2021

There is no vulnerability here, so it will not be addressed.
#11174

@gaearon gaearon closed this as completed Jul 7, 2021
@facebook facebook locked as resolved and limited conversation to collaborators Jul 7, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants