Skip to content

React-Scripts dependencies with CVEs #8529

Closed
@kevinfealey

Description

@kevinfealey

Is your proposal related to a problem?

Snyk reports vulnerabilities in react-scripts dependency tree:

✗ Medium severity vulnerability found in dot-prop

Description: Prototype Pollution
Info: https://snyk.io/vuln/SNYK-JS-DOTPROP-543489

Introduced through: [email protected]
From: [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
From: [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
From: [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
Fixed in: 5.1.1

✗ Medium severity vulnerability found in @hapi/hoek

Description: Prototype Pollution
Info: https://snyk.io/vuln/SNYK-JS-HAPIHOEK-548452

Introduced through: [email protected]
From: [email protected] > [email protected] > [email protected] > @hapi/[email protected] > @hapi/[email protected]
From: [email protected] > [email protected] > [email protected] > @hapi/[email protected] > @hapi/[email protected] > @hapi/[email protected]
Fixed in: 8.5.1, 9.0.3

Please note that although the above references [email protected], v3.4.0 has not updated these dependencies and therefore has the same problem.

Describe the solution you'd like

Release a new version of react-scripts that updates to the latest versions of workbox-webpack-plugin and optimize-css-assets-webpack-plugin, which should resolve this issue.

Describe alternatives you've considered

None

Additional context

N/A

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions