-
-
Notifications
You must be signed in to change notification settings - Fork 323
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
found 1 high severity vulnerability #96
Labels
bug
Something isn't working
Comments
Thanks for raising this issue.
This is used in build time, which should be a less risk vulnerability. Prefer to raise this issue in workbox project as I'm not sure if I update it here, if it will break some scenarios. |
Just opened an issue here: |
Resolved |
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
Summary
High | Remote Code Execution
Package | serialize-javascript
Patched in | >=3.1.0
Dependency of | next-pwa
Path | next-pwa > workbox-webpack-plugin > workbox-build > rollup-plugin-terser > serialize-javascript
More info | https://npmjs.com/advisories/1548
How To Reproduce
Steps to reproduce the behavior:
npm install --save next-pwa
npm audit
Link to minimal reproduce setup repository if any.
Expected Behaviors
The lib to be updated and do not have this critical vulnerability
The text was updated successfully, but these errors were encountered: