-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug][PDFViewer] Bump PDF.js version #2237
Comments
+1 - this is halting our deployments to production |
From my investigation is appears to be |
does version Many thanks, |
Hello, James, We have bumped the version of kendo-pdfviewer-common to 0.2.10 in order to avoid the vulnerability We've decided to postpone the update to 4.x due to compatibility issues that break user applications. We'll be able to proceed once mozilla/pdf.js#18051 is merged and released. For the time being, we've mitigated the security vulnerability by setting isEvalSupported: false, as suggested in the CVE-2024-4367 security advisory, the fix will be available in the newest version |
Hey @filipKovachev thank you for getting in touch and clarifying the roadmap for the fix, hopefully Mozilla address ASAP. Despite installing version 8 of Will this be the case until the upgrade to 4.x has taken place in |
Upgrading to Upgrading to In the
|
Hi @jamesryan-dev Related issue for more information: #2306 |
The version of PDF.js is bumped in the latest development version of the @progress/kendo-react-pdf-viewer package. The Kendo React suite's official version will be released next week. |
I'm submitting a...
Current behavior
Currently running npm audit results in the following error:
This is an issue with PDF.js, it seems that bumping the version to 4.2.67 should resolve it: GHSA-wgrm-67xf-hhpq
Expected behavior
When running npm audit this error should not appear.
Minimal reproduction of the problem with instructions
npm audit
Reported in Ticket ID: 1651157
The text was updated successfully, but these errors were encountered: