batchelor icon indicating copy to clipboard operation
batchelor copied to clipboard

Potential crashes with "dicer" dependency

Open mpacary opened this issue 1 year ago • 0 comments

Hello,

Using dicer dependency may result in crashes, according to npm when running npm install with batchelor 2.0.2 in package.json:

dicer  *
Severity: high
Crash in HeaderParser in dicer - https://github.com/advisories/GHSA-wm7h-9275-46v2
No fix available
node_modules/dicer
  batchelor  *
  Depends on vulnerable versions of dicer
  node_modules/batchelor

Please check the corresponding issue opened in dicer repo. A PR on dicer is opened since more than one year, a quick fix should not be expected on that side...

mpacary avatar Oct 21 '22 12:10 mpacary