Skip to content

Depending on vulnerable version of cosmiconfig #192

@imnasnainaec

Description

@imnasnainaec
  • babel-plugin-macros version: v3.1.0
  • node version: v18.15.0
  • npm version: v9.5.0

In package.json:

  "dependencies": {
    "cosmiconfig": "^7.0.0",

What you did:
npm audit

What happened:

  cosmiconfig  6.0.0 - 7.1.0
  Depends on vulnerable versions of yaml

Problem description:

babel-plugin-macros depends on an older version of cosmicconfig which has a vulnerability.

Suggested solution:

Update cosmicconfig (at this time, v8.1.3 is available).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions