html-webpack-plugin
html-webpack-plugin copied to clipboard
Update version of html-minifier-terser dependency
Current version of html-minifier-terser depends on outdated version of terser vulnerable to ReDOS. [email protected] depends on terser ^5.14.2, which addresses the vulnerability.
can we get this security vulnerability fix released?
Would be great if @jantimon or @mastilver Could take a look so this vulnerability fix can be merged and released. Thank you!
I have solved this issue. There are some cached codes in a lock file. Remove lock file and node_modules. Then install them, and compare lock files. FYI. https://github.com/webpack/webpack/issues/16306#issuecomment-1290527482
Any updates? Still getting dependabot vulnerability alerts because of this dependency :(