Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

babel-preset-react security vulnerability #4

Open
jairuzu opened this issue Jul 26, 2019 · 2 comments
Open

babel-preset-react security vulnerability #4

jairuzu opened this issue Jul 26, 2019 · 2 comments

Comments

@jairuzu
Copy link
Contributor

jairuzu commented Jul 26, 2019

According to yarn audit --groups dependencies, the babel-preset-react dependency has a high security vulnerability due to lodash.

@joeldenning @blittle is there a specific reason that babel-preset-react is a dependency instead of a devDependency?

@joeldenning
Copy link
Contributor

No there is no reason. It should be a devDependency. Additionally, while you're at it, you should probably upgrade to @babel/preset-react (and babel 7 in general 😄 )

@jairuzu
Copy link
Contributor Author

jairuzu commented Jul 26, 2019

Thanks for confirming! 👍

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants