You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Dec 26, 2023. It is now read-only.
I got dependabot alert in my project referencing webpack-pwa-manifest v4.3.0:
xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
[email protected] requires xml2js@^0.4.5 via a transitive dependency on [email protected]
No patched version available for xml2js
The earliest fixed version is 0.5.0.
parse-bmfont-xml project seems to be unsupported. Could a reference to it be replaced by something else?
The text was updated successfully, but these errors were encountered:
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Hi!
I got dependabot alert in my project referencing webpack-pwa-manifest v4.3.0:
parse-bmfont-xml project seems to be unsupported. Could a reference to it be replaced by something else?
The text was updated successfully, but these errors were encountered: