-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Flot-axis still in Yarn.lock file under Components folder #9700
Comments
#9187 Potentially false positive: But since all references and usage of flot-axislabels was removed in latest update, potentially still worth cleaning up lingering reference in lockfile |
manuel-sommer
added a commit
to manuel-sommer/django-DefectDojo
that referenced
this issue
Mar 10, 2024
Merged
mtesauro
pushed a commit
that referenced
this issue
Mar 11, 2024
This can be close @mtesauro ;-) was already released. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Flot-axis was removed from everywhere except yarn.lock.
It's a malicious package with a Synk rating of 9.8/10 Criticality.
Please hotfix for part of latest release that was meant to address this issue!
Thank you guys for your hard work
The text was updated successfully, but these errors were encountered: