Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in eta #3354

Closed
makkes opened this issue Feb 2, 2023 · 3 comments · Fixed by #3367
Closed

Vulnerabilities in eta #3354

makkes opened this issue Feb 2, 2023 · 3 comments · Fixed by #3367
Assignees
Labels
bug Something isn't working ci

Comments

@makkes
Copy link
Member

makkes commented Feb 2, 2023

Snyk is reporting vulnerabilities for one of docusaurus' dependencies:

  1/7: Cross-site Scripting (XSS) [Medium Severity]
    Via: @docusaurus/core@2.3.0 => eta@1.12.3
    Fixed in: eta 2.0.0
[...]

Example run that failed.

This currently leads to CI check failures on any PRs.

@Callisto13
Copy link
Contributor

Docusaurus merged the bump yesterday facebook/docusaurus#8610

@makkes
Copy link
Member Author

makkes commented Feb 2, 2023

Let's hope they don't stick to their past release candence to get this out.

@makkes makkes self-assigned this Feb 2, 2023
@makkes
Copy link
Member Author

makkes commented Feb 3, 2023

Judging by the PRs merged at this very moment it looks like 2.3.1 will be released soon. Let's wait for that to happen so we can easily upgrade without having to pin transitive deps.

makkes pushed a commit that referenced this issue Feb 6, 2023
@makkes makkes added the bug Something isn't working label Feb 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working ci
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants