Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade immer in react-dev-utils #11454

Closed
wants to merge 3 commits into from
Closed

Conversation

leleabhinav
Copy link

@leleabhinav leleabhinav commented Sep 17, 2021

Upgrades immer and bump version for react-dev-utils

@leleabhinav leleabhinav changed the title Upgrade immer Upgrade immer in react-dev-utils Sep 17, 2021
@petetnt
Copy link
Contributor

petetnt commented Sep 18, 2021

Hi @leleabhinav, thanks for the PR! There's already a dependabot PR tracking this, so closing this is as duplicate of #11364 :)

@petetnt petetnt closed this Sep 18, 2021
@davilima6
Copy link

davilima6 commented Nov 7, 2021

Can we reopen this PR considering

  • it fixes a critical vulnerability from immer <= 9.0.5
  • the Dependabot's PR has a wider scope, is marked as stale, is red on CI and looks not trivial to merge
$ npm audit
...
immer  <=9.0.5
Severity: critical
Prototype Pollution in immer - https://github.com/advisories/GHSA-33f9-j839-rf8h
Prototype Pollution in immer - https://github.com/advisories/GHSA-9qmh-276g-x5pj

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants