Skip to content
This repository was archived by the owner on Dec 25, 2024. It is now read-only.

Conversation

@nterray
Copy link
Contributor

@nterray nterray commented Jun 5, 2023

Description

@antfu/utils under 0.7.3 are vulnerable to CVE-2023-2972

We should bump its usage in unplugin-vue2-script-setup and create a new release.

@antfu/utils under 0.7.3 are vulnerable to [CVE-2023-2972][0]

We should bump its usage in unplugin-vue2-script-setup and create a new
release.

[0]: https://osv.dev/vulnerability/GHSA-p2fh-2h23-6grg
@antfu antfu changed the title fix: Bump @antfu/utils 0.5.2 -> 0.7.4 fix: bump @antfu/utils 0.5.2 -> 0.7.4 Jun 5, 2023
@antfu antfu merged commit 7cf73f2 into unplugin:main Jun 5, 2023
@nterray nterray deleted the bump-antfu-utils branch June 5, 2023 11:35
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants