Skip to content

Track upstream to solve CVE-2021-3803#1

Open
joshuanapoli wants to merge 3 commits intorpl:scoped-package-masterfrom
CumulusDS:svgo
Open

Track upstream to solve CVE-2021-3803#1
joshuanapoli wants to merge 3 commits intorpl:scoped-package-masterfrom
CumulusDS:svgo

Conversation

@joshuanapoli
Copy link

@joshuanapoli joshuanapoli commented Sep 21, 2021

Pull yahoo#21 to upgrade svgo to upgrade transitive dependency nth-check to v2.0.1. This fixes CVE-2021-3803.

This is a step towards solving rpl/flow-coverage-report#206.

rpl and others added 3 commits December 15, 2018 17:45
…ad `css-select` -> `css-what`)

The vulnerability is described at https://snyk.io/vuln/SNYK-JS-CSSWHAT-1298035

Also:
1. updates devDeps.
2. fixes problem with numeric entities for `<` and `&` not being permissible when they should be (needed to keep a test passing as well as being a proper fix)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants