Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Publish new version of react-scripts #6752

Closed
marthall opened this issue Apr 4, 2019 · 2 comments
Closed

Publish new version of react-scripts #6752

marthall opened this issue Apr 4, 2019 · 2 comments

Comments

@marthall
Copy link

marthall commented Apr 4, 2019

Is this a bug report?

No. Request for publish of new version of react-scripts

Issue

Snyk reports a vulnerability for react-scripts@2.1.8 through the dependencies react-scripts@2.1.8 › jest@23.6.0 › jest-cli@23.6.0 › istanbul-api@1.3.7 › istanbul-reports@1.5.1 › handlebars@4.0.12

The issue is this dependency of react-scripts@2.1.8: https://github.com/facebook/create-react-app/blob/v2.1.8/packages/react-scripts/package.json#L51

This dependency is bumped and fixed in #6278 but there is not a new version on https://www.npmjs.com/package/react-scripts

Could you publish a new version of react-scripts?

@iansu
Copy link
Contributor

iansu commented Apr 4, 2019

This will be fixed in the 3.0 release, which should be available soon. We are not planning any more releases of the 2.x version. In the meantime you can try an alpha release of 3.0 here: #6475

@iansu iansu closed this as completed Apr 4, 2019
@marthall
Copy link
Author

marthall commented Apr 4, 2019

Thanks for the quick response 👍

@lock lock bot locked and limited conversation to collaborators Apr 9, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants