This repository was archived by the owner on Sep 7, 2020. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 11
This repository was archived by the owner on Sep 7, 2020. It is now read-only.
Critical Vulnerability in outdated version of webpack-dev-server #10
Copy link
Copy link
Open
Description
This library is causing some issues with your downstream components:
$ npm audit
=== npm audit security report ===
┌──────────────────────────────────────────────────────────────────────────────┐
│ Manual Review │
│ Some vulnerabilities require your attention to resolve │
│ │
│ Visit https://go.npm.me/audit-guide for additional guidance │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ graphql-playground-react │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ graphql-playground-react > graphcool-styles > │
│ │ webpack-dev-server > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/663 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ graphql-playground-react │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ graphql-playground-react > graphcool-tmp-ui > │
│ │ graphcool-styles > webpack-dev-server > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://nodesecurity.io/advisories/663 │
└───────────────┴──────────────────────────────────────────────────────────────┘
found 2 critical severity vulnerabilities in 19590 scanned packages
2 vulnerabilities require manual review. See the full report for details.
Recommend updating webpack-dev-server to avoid confusion people might start getting with security advisories.
Metadata
Metadata
Assignees
Labels
No labels