Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade babel deps to fix security vuln in babel traverse #80

Closed
imoby opened this issue Nov 10, 2023 · 3 comments
Closed

Upgrade babel deps to fix security vuln in babel traverse #80

imoby opened this issue Nov 10, 2023 · 3 comments
Labels
dependencies Pull requests that update a dependency file
Milestone

Comments

@imoby
Copy link

imoby commented Nov 10, 2023

Can we update the deps for babel to > 7.23.2 to fix the babel traverse vuln: GHSA-67hx-6x53-jw92

@movoid12
Copy link

Good point. I did that already for a project by running:

pnpm audit fix

And i was able to update that and override and fix babel traverse vuln

@mrmckeb
Copy link
Contributor

mrmckeb commented Dec 11, 2023

Thanks @movoid12, yes we left peers unpinned to enable people to upgrade.

I'll make this change soon in the package - thanks again!

@mrmckeb mrmckeb added this to the v6 milestone Mar 4, 2024
@mrmckeb mrmckeb added the dependencies Pull requests that update a dependency file label Mar 4, 2024
@mrmckeb
Copy link
Contributor

mrmckeb commented Mar 5, 2024

I forgot to link this, but it should have been solved by this merge, and will be in v6.0.
#97

@mrmckeb mrmckeb closed this as completed Mar 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

3 participants