Skip to content

release new version with up-to-date deps #109

@hacknug

Description

@hacknug

Running pnpm audit reports a moderate vulnerability coming from the old version of @sanity/ui that @frontvibe/sanity-plugin-range-slider uses (I guess this will also affect other packages in the monorepo but I haven't checked since I do not use them).

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate            │ PrismJS DOM Clobbering vulnerability                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ prismjs                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.30.0                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=1.30.0                                               │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ packages__backend>@frontvibe/sanity-plugin-range-      │
│                     │ slider>@sanity/ui>react-refractor>refractor>prismjs    │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-x7hr-w5r2-h6wg      │
└─────────────────────┴────────────────────────────────────────────────────────┘

It would be great if all dependencies could be updated and a new version of the packages released.

Let me know if I can help with anything 👍

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions