react-refresh-webpack-plugin
react-refresh-webpack-plugin copied to clipboard
Security vulnerability - loader-utils 2.0.4
loader-utils: 2.0.4 has the dependency JSON5: 2.1.2
it causes Prototype Pollution in JSON5 via Parse Method
Most probably not a real risk, see also https://overreacted.io/npm-audit-broken-by-design/
Unfortunately since we still support WDS v3 it is likely impossible to fix. Probably something for 0.6.x.
Will be fixed in v0.6.0.