cli icon indicating copy to clipboard operation
cli copied to clipboard

nested dependency es5-ext has a security vulnerability (low) and needs update

Open fredericpellin opened this issue 1 year ago • 1 comments

es5-ext has vulnerability CVE-2024-27088

update has been done on es5-ext

Is it possible to update sequelize to use 0.10.63 of es5-ext ?

fredericpellin avatar Feb 27 '24 05:02 fredericpellin

As far as I can see on the lockfile of our latest release (6.6.2), our dependencies do not have es5-ext pinned so if you refresh your lockfile it should be able to update to 0.10.63 already.

WikiRik avatar Feb 27 '24 10:02 WikiRik