Skip to content

Commit 158f388

Browse files
authored
fix: remove pinned async dev dependency from default package.json (#22321)
The async dependency was originally added in PR #13547 to fix a Prototype Pollution security vulnerability. This is no longer needed as the vulnerability has been resolved in newer versions and there are no direct dependencies requiring async. Fixes #21507
1 parent c9e5d68 commit 158f388

File tree

2 files changed

+0
-2
lines changed

2 files changed

+0
-2
lines changed

flow-server/src/main/resources/com/vaadin/flow/server/frontend/dependencies/default/package.json

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,6 @@
88
"lit": "3.3.1"
99
},
1010
"devDependencies": {
11-
"async": "3.2.6",
1211
"glob": "11.0.3",
1312
"typescript": "5.9.2",
1413
"workbox-core": "7.3.0",

flow-server/src/test/java/com/vaadin/flow/server/frontend/NodeUpdaterTest.java

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,6 @@ private Set<String> getCommonDevDeps() {
179179
expectedDependencies.add("workbox-core");
180180
expectedDependencies.add("workbox-precaching");
181181
expectedDependencies.add("glob");
182-
expectedDependencies.add("async");
183182
return expectedDependencies;
184183
}
185184

0 commit comments

Comments
 (0)