yarn audit fails due to cli dependency `size-plugin`.
See original GitHub issueDo you want to request a feature or report a bug? Bug
What is the current behaviour?
Dependency from preact-cli
, size-plugin
, cause yarn audit
to fail from an axios
vulnerability.
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ high โ Server-Side Request Forgery โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ axios โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Patched in โ >=0.21.1 โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ preact-cli โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ preact-cli > size-plugin > axios โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://www.npmjs.com/advisories/1594 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
If the current behaviour is a bug, please provide the steps to reproduce.
What is the expected behaviour?
yarn audit
should be passed
If this is a feature request, what is motivation or use case for changing the behaviour?
Please mention other relevant information.
Please paste the results of preact info
here.
Environment Info: System: OS: macOS 10.15.7 CPU: (8) x64 Intelยฎ Coreโข i7-8559U CPU @ 2.70GHz Binaries: Node: 14.8.0 - /usr/local/bin/node Yarn: 1.22.4 - /usr/local/bin/yarn npm: 6.14.7 - /usr/local/bin/npm Browsers: Chrome: 87.0.4280.141 Firefox: 80.0.1 Safari: 14.0.1
Issue Analytics
- State:
- Created 3 years ago
- Reactions:1
- Comments:10 (5 by maintainers)
Top GitHub Comments
The PR to fix this upstream has been merged in, so the โvulnerabilityโ should be gone. Closing this.
Let me know if anyone is still having issues. You might need to regen your lock files.
Oops, I must be blind to not see this ๐
Let me change the description of this quickly
Thanks for your quick reply ๐