We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
High Code Injection
Package js-yaml
Patched in >=3.13.1
Dependency of babel-plugin-inline-react-svg
Path babel-plugin-inline-react-svg > svgo > js-yaml
More info https://npmjs.com/advisories/813
The text was updated successfully, but these errors were encountered:
airbnb/babel-plugin-inline-react-svg#64
Currently listed as false positive in npm audit. Bable requires this process to be synchronous and the reason they aren't updating.
The reason this is not considered a security risk is highlighted here: airbnb/babel-plugin-inline-react-svg#59
Sorry, something went wrong.
If the js-yaml package is getting shipped in the production build you can look at things like: https://github.com/bhovhannes/svg-url-loader
I assume at some point they will get tired of getting issues related to that and just either kill the dep or find a way to bump the version.
No branches or pull requests
High Code Injection
Package js-yaml
Patched in >=3.13.1
Dependency of babel-plugin-inline-react-svg
Path babel-plugin-inline-react-svg > svgo > js-yaml
More info https://npmjs.com/advisories/813
The text was updated successfully, but these errors were encountered: