You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We now have 2 component governance alerts related to security issues with the dependencies of @uifabric/example-app-base:
These issues include:
Prism 1.17.1 - pulled in via refractor v 2.10.1, which is a dependency of react-syntax-highlighter v10.3.5. Updating to react-syntax-highlighter 13.3.1 addresses this issue. Advisory
markdown-to-jsx 6.6.1. Updating to 6.11.4 or later addresses this. Advisory
The text was updated successfully, but these errors were encountered:
@christiango I have a PR out that updates the markdown-to-jsx package version. Regarding the react-syntax-highlighter package, we've chosen not to upgrad
e it since it would lead to duplicated package versions due to the fact that it is also pulled from @storybook/components. We've chosen to do this given that we don't actively use prism which is the package that is triggering the vulnerability.
We now have 2 component governance alerts related to security issues with the dependencies of @uifabric/example-app-base:
These issues include:
The text was updated successfully, but these errors were encountered: