Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in is-js #190

Closed
nukeop opened this issue Feb 1, 2024 · 1 comment · Fixed by #191
Closed

Vulnerability in is-js #190

nukeop opened this issue Feb 1, 2024 · 1 comment · Fixed by #191
Assignees
Labels

Comments

@nukeop
Copy link

nukeop commented Feb 1, 2024

There is a high severity vulnerability in the is_js dependency: GHSA-pvrw-g6fx-mcx2

It shouldn't really be needed anymore since these functionalities are part of JS and can probably be removed from the project altogether as it hasn't been updated in years.

@mikejpeters mikejpeters self-assigned this Feb 7, 2024
mikejpeters added a commit that referenced this issue Feb 7, 2024
mikejpeters added a commit that referenced this issue Feb 19, 2024
fix: remove vulnerable dependency

fixes #190
Copy link

🎉 This issue has been resolved in version 4.0.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants