Skip to content
This repository has been archived by the owner on Sep 10, 2022. It is now read-only.

New patch required to mitigate high risk vulnerability #866

Open
andreasonny83 opened this issue May 18, 2022 · 0 comments
Open

New patch required to mitigate high risk vulnerability #866

andreasonny83 opened this issue May 18, 2022 · 0 comments

Comments

@andreasonny83
Copy link

andreasonny83 commented May 18, 2022

@istarkov, the fbjs dependency was removed time ago and the PR is already merged into master. However, the latest 0.30.0 version of recompose is still injecting that package inside as it doesn't contain the latest changes to the package.json.
The fbjs is currently pulling inside a vulnerable version of node-fetch making any package consuming recompose as High risk.
Can you please trigger a new release to finally get rid of that extra dependency?
Thank you

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant