Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump browser-sync to v3.0.2 #1

Merged
merged 1 commit into from
Apr 25, 2024
Merged

bump browser-sync to v3.0.2 #1

merged 1 commit into from
Apr 25, 2024

Conversation

PseudoNinja
Copy link
Owner

Resolve Cross-Site Request Forgery Vulnerability in browser-sync@2.29.3

axios 0.8.1 - 0.27.2
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
No fix available
node_modules/axios
localtunnel >=1.9.0
Depends on vulnerable versions of axios
node_modules/localtunnel
browser-sync 2.24.0-rc1 - 3.0.0-alpha.2
Depends on vulnerable versions of localtunnel
node_modules/browser-sync
lite-server *
Depends on vulnerable versions of browser-sync
node_modules/lite-server

@PseudoNinja PseudoNinja added the security Security Fixes label Apr 25, 2024
@PseudoNinja PseudoNinja merged commit 5febad3 into main Apr 25, 2024
@PseudoNinja PseudoNinja deleted the fix/upgrade-lite-server branch April 25, 2024 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Security Fixes
Projects
None yet
1 participant