Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Loader Utils to 2.0.4 to fix a vulnerability in v5 #228

Closed
wants to merge 1 commit into from
Closed

Conversation

mmalka
Copy link

@mmalka mmalka commented Dec 1, 2022

Fixes #226 in v5 (the version used by Angular 14.X)
(doesn't require an update to 3.0 like the issues mentions)

@mmalka mmalka changed the title Update Loader Utils to 2.0.4 to fix a vulnerability Update Loader Utils to 2.0.4 to fix a vulnerability in v5 Dec 1, 2022
@mmalka
Copy link
Author

mmalka commented Dec 1, 2022

@bholloway Hello Ben, here you go.

@bholloway
Copy link
Owner

This should not be necessary given the carat allows patch in your local install.

I have a PR to update dependencies in general so I will close this and focus on #227.

@bholloway bholloway closed this Dec 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

loader-utils dependency v2 is vulnerable and should be updated to v3: CVE-2022-37599
2 participants