Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-37601 and CVE-2021-44906 #3339

Open
jkacmaz93 opened this issue Jul 30, 2024 · 0 comments
Open

CVE-2022-37601 and CVE-2021-44906 #3339

jkacmaz93 opened this issue Jul 30, 2024 · 0 comments

Comments

@jkacmaz93
Copy link

Hi, vulnerability scanner detected two dependencies in the yarn.lock file as vulnerable version referenced.

Minimist:
CVE-2021-44906 - The vulnerability can be remediated by updating the library to version 1.2.6 or higher.
See:

minimist@^1.2.0, minimist@^1.2.5:

Loader-Utils:
CVE-2022-37601 - The vulnerability can be remediated by updating the library to version 2.0.3 or higher.
See :

loader-utils@^2.0.0:

See:
loader-utils@^1.1.0, loader-utils@^1.2.3, loader-utils@^1.4.0:

Ruby version: 3.2.0
Webpacker version: 5.4.3

Desired behavior: Could you update these two dependencies to the non-vulnerable versions? Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant