CVE-2023-44270 on package dependencies
Hello, i have alert from scanning about dependencie postcss. component-compiler-utils use "postcss": "^7.0.36", but "id":"CVE-2023-44270","package":"postcss","version":"7.0.39","fix_version":"8.4.31","severity":"Medium"
Please update to [email protected]
See also #122
Seconding this request
+1
samsies. seconding this
Seconding the request. Is this project still maintained?
Any update regarding this issue? Over 3 months are passed...
+1
I would be really nice to have this one final update. All other subpackages of @vue/[email protected] are using the newer postcss version 8.4.31.
Updating the version of postcss in package.json and releasing a new minor version would make quite a few maintainers of legacy Vue apps happy.
`
Hello, Any update package yet? Seconding this request
Any updates? Seconding this...
Hi, there,
I tried a pull request #140 for updating postcss to version 8.4.49 as well as migrating plugins from version 7 to 8, pending.