Bundle Analysis Tools are riddled with vulnerabilities #914
matthewtusker
started this conversation in
General
Replies: 2 comments
-
|
The vulnerabilities exist in bundler-plugin-core, so they affect all Javascript bundle analysis tools, not just the Webpack plugin. |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Yeah, I am also getting alerts on issues from npm. 5 High-severity vulnerabilities in undici:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Dependabot is screaming at us because the Webpack Bundle Analysis plugin is pulling in vulnerable dependencies. There have been no commits to that repo in 10 months, is it dead? Am I supposed to remove it and stop using bundle analysis? I've asked in that repo (started a discussion, raised an issue listing the vulnerabilities) and have had zero response.
Beta Was this translation helpful? Give feedback.
All reactions