Upgrade semver from 6.3.0 to 6.3.1 #1253
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi there,
I just checked out this repository to learn more about the overall architecture of heroicons, especially since I need to build my own iconset (mainly for React). While installing the dependencies I saw that semver needs to be updated to 6.3.1 due to a high severity vulnerability.
Here's the link to the vulnerability: https://security.snyk.io/package/npm/semver/6.3.0
I ran
npm audit fix
to fix this problem :)