Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fsevents package has a critical vulnerablity #154

Open
KwesiByrd opened this issue Feb 27, 2025 · 0 comments
Open

Fsevents package has a critical vulnerablity #154

KwesiByrd opened this issue Feb 27, 2025 · 0 comments

Comments

@KwesiByrd
Copy link

I've recently gotten the following alert from a security scanning tool we used on our Craft App

The library fsevents version 1.2.9 was found in src/assetbundles/jasonfield/yarn.lock on line 3961 and is vulnerable to CVE-2023-45311, which exists in versions <= 1.2.10.

GHSA-8r6j-v8pm-fqw3

When you get a chance, could you please bump the package to v 1.2.11 or higher?

Thanks in advance

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant