Skip to content

Vulnerable dependency [email protected] in pnpm-lock.yaml  #14854

@JackMcBride98

Description

@JackMcBride98

image

It's odd that there are two versions of lilconfig in the pnpm-lock.yaml

Versions before 3.1.1 are vulnerable to "Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function"
src

Having cloned the repo and looked at the git history it appears this was caused by PR #14769 @adamwathan

The project I'm working on has strict security requirements, so would appreciate if this could get fixed :)

Thanks for all your hard work. Absolutely love tailwindcss 😍

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions