You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependabot cannot update hosted-git-info to a non-vulnerable version
The latest possible version that can be installed is 2.8.9 because of the following conflicting dependencies:
@vue/cli-plugin-babel@4.4.6 requires hosted-git-info@^2.1.4 via a transitive dependency on normalize-package-data@2.5.0
@vue/cli-plugin-eslint@4.4.6 requires hosted-git-info@^2.1.4 via a transitive dependency on normalize-package-data@2.5.0
@vue/cli-service@4.4.6 requires hosted-git-info@^2.1.4 via a transitive dependency on normalize-package-data@2.5.0
@vue/cli-shared-utils@4.4.6 requires hosted-git-info@^2.1.4 via a transitive dependency on normalize-package-data@2.5.0
node-sass@5.0.0 requires hosted-git-info@^2.1.4 via a transitive dependency on normalize-package-data@2.5.0
The earliest fixed version is 3.0.8.
View logs or learn more about troubleshooting Dependabot errors.
概要
フロントエンドを作ってから1年くらいが経ち、脆弱性のあるnpmパッケージを簡単にアップグレードできなくなってしまった。
https://github.com/selelab/admin/security/dependabot/front/yarn.lock/hosted-git-info/open
hosted-git-info
の場合、すでにdeprecatedとなったパッケージであるnode-sass
に依存していることが根本的な原因である。The text was updated successfully, but these errors were encountered: