webpacker icon indicating copy to clipboard operation
webpacker copied to clipboard

chore: address CVE-2023-45133 in major version 5

Open springerigor opened this issue 7 months ago • 1 comments

The vulnerability was found by our security scanner. It has already been patched in version 6, but we would like to stick to major version 5 for now.

The similar PRs (https://github.com/rails/webpacker/pull/3330, https://github.com/rails/webpacker/pull/3334) change too many things at once.

springerigor avatar May 15 '25 12:05 springerigor

@amatsuda Would it be possible to have this patch released to version 5?

springerigor avatar May 15 '25 13:05 springerigor