Skip to content

Dependency on loader-utils 1.1.0 is security concern, CRITICAL vulnerabilities #502

@Branpolo

Description

@Branpolo

Packages.json includes a dependency on loader-utils ^1.1.0 however there are some severe vulnerabilities with this version see https://security.snyk.io/package/npm/loader-utils/1.1.0 (or: GitHub's dependabot scanner)

Even if this package doesn't expose these vulnerabilities, having this dependency blocks other packages from using later loader-utils versions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions