-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Running pnpm audit reports a moderate vulnerability coming from the old version of @sanity/ui that @frontvibe/sanity-plugin-range-slider uses (I guess this will also affect other packages in the monorepo but I haven't checked since I do not use them).
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate │ PrismJS DOM Clobbering vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ prismjs │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ packages__backend>@frontvibe/sanity-plugin-range- │
│ │ slider>@sanity/ui>react-refractor>refractor>prismjs │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-x7hr-w5r2-h6wg │
└─────────────────────┴────────────────────────────────────────────────────────┘
It would be great if all dependencies could be updated and a new version of the packages released.
Let me know if I can help with anything 👍
Metadata
Metadata
Assignees
Labels
No labels