-
Notifications
You must be signed in to change notification settings - Fork 69
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
loader-utils dependency v2 is vulnerable and should be updated to v3: CVE-2022-37599 #226
Comments
Fix is currently blocked. See attached PR. |
The fix has been backported to v2 of Either way @bholloway I don't think there's any further action required from you, unless you'd be willing to look into seeing if v3 could be upgraded to use v2 of |
a v1 version of |
Fixed by #229 |
Hello,
as the webpack loader-utils v2 are vulnerable, we get issues when installing resolve-url-loader. Could you please provide an update with the upgraded to v3 loader-utils package?
Link to more vulnerability details
https://nvd.nist.gov/vuln/detail/CVE-2022-37599
The text was updated successfully, but these errors were encountered: