-
Notifications
You must be signed in to change notification settings - Fork 3.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cross-site Scripting (XSS) via Data URIs - snyk notifications #863
Comments
We are waiting for #844 to be pushed by the maintainer. |
I am keeping this one open until the change is pushed, but I wanted to rename the ticket to make it more search friendly. |
This seems important enough to cut a new release for. Any reason that isn't being done? |
@chjj @matt- @paulirish Any word on getting a tag for this fix? |
0.3.7 finally came out, and did include the previous submitted fixes. Unfortunately, there's still one high-severity vulnerability that is supposed to be addressed by the upcoming 0.3.9 release. |
Believe 0.3.9 corrects all these issues. Please confirm and comment, if incorrect. |
✗ High severity vulnerability found on [email protected]
Fix: None available. Consider removing this dependency.
✗ High severity vulnerability found on [email protected]
Fix: None available. Consider removing this dependency.
✗ High severity vulnerability found on [email protected]
Fix: None available. Consider removing this dependency.
The text was updated successfully, but these errors were encountered: