-
-
Notifications
You must be signed in to change notification settings - Fork 170
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
esbuild security issue #700
Comments
Open PR: #698 |
|
This issue blocks any pipeline which includes
The exit code is to prevent builds from being deployed with vulnerable code. Even though in this case the code is not used, the pipeline will still be blocked until either:
|
While I also hope #698 is accepted, the maintainer seems to have a stance on these kinds of updates, so I don't hold my breath. See comments in #615. A workaround that I use when package versions are compatible is to override the transitive dependency version in For example, add this to
and then run |
Closed via #698 |
May we get esbuild updated to 0.25.0 to address GHSA-67mh-4wv8-2f99?
The text was updated successfully, but these errors were encountered: