🐛 Bug: Bump serialize-javascript from 6.0.0 to 6.0.2 #5109
Labels
status: accepting prs
Mocha can use your help with this one!
type: bug
a defect, confirmed by a maintainer
Bug Report Checklist
faq
label, but none matched my issue.Expected
Adding a dependency to the Mocha package should not introduce security vulnerabilities.
Actual
If your project uses Snyk to protect against security vulnerabilities, the Mocha dependency is flagged as problematic due to an explicit lock on serialize-javascript 6.0.0
https://security.snyk.io/package/npm/serialize-javascript
Minimal, Reproducible Example
Refer to https://security.snyk.io/package/npm/serialize-javascript for the vulnerable versions of this package.
Versions
From
package-lock.json
I checked the latest Mocha
package-lock.json
though, and theserialize-javascript
version is still at 6.0.0.Additional Info
No response
The text was updated successfully, but these errors were encountered: