-
-
Notifications
You must be signed in to change notification settings - Fork 190
Open
Description
Guys, we are using a dependency called svg-inline-loader which is using [email protected] which seems to be using [email protected] and since svg-inline-loader version we are using is the latest one, we would need for loader-utils to be on a version that is using a json5 version where the CVE has been patched or perhaps a version not needing that dependency at all.
Could you please advise as we need to resolve these vulnerabilities as soon as possible.
Metadata
Metadata
Assignees
Labels
No labels