workbox icon indicating copy to clipboard operation
workbox copied to clipboard

Vulnerability in @babel/[email protected] due to @babel/[email protected]

Open diveshpanwar opened this issue 2 years ago • 1 comments

Library Affected: [email protected] @babel/[email protected] @babel/[email protected]

Browser & Platform: all browsers

Issue or Feature Request Description: The reported version of [email protected] uses a version of @babel/[email protected] which depends on @babel/[email protected]. This babel traverse version is said to have a severe vulnerability as reported here NVD Bug Description and Github Advisory.

Since this is a severe vulnerability it is being flagged by many vulnerability detection tools.

Kindly consider upgrading the @babel/core version to >=7.23.2 or please suggest a workaround.

diveshpanwar avatar Oct 17 '23 08:10 diveshpanwar

I concur, there is a PR https://github.com/GoogleChrome/workbox/pull/3265 waiting for approval, hopefully it will go through soon

vitalij931 avatar Oct 31 '23 10:10 vitalij931

Hi there,

Workbox is moving to a new engineering team within Google. As part of this move, we're declaring a partial bug bankruptcy to allow the new team to start fresh. We realize this isn't optimal, but realistically, this is the only way we see it working. For transparency, here're the criteria we applied:

Thanks, and we hope for your understanding! The Workbox team

tomayac avatar Apr 25 '24 08:04 tomayac