Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

has transitive dependencies with a CVE vulnerability #22

Open
vdhpieter opened this issue Dec 15, 2021 · 0 comments
Open

has transitive dependencies with a CVE vulnerability #22

vdhpieter opened this issue Dec 15, 2021 · 0 comments

Comments

@vdhpieter
Copy link

vdhpieter commented Dec 15, 2021

This package depends on @storybook/components@5.3.21 following the dependency chain this pull is vulnerable versions of highlight.js: GHSA-7wwv-vh3v-89cq & GHSA-vfrc-7r7c-w9mx. Updating to the last version of @storybook/components will fix this

Updating this wil also remove the dependency on a vulnerable version of prismjs GHSA-hqhp-5p83-hx96.

Do you accept a PR? I can always try to fix this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant