Commit 1ea7d99
committed
[build] Fix vulnerability in serialize-javascript <=7.0.2
```
npm audit report
serialize-javascript <=7.0.2
Severity: high
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() - GHSA-5c6j-r48x-rmvq
fix available via `npm audit fix --force`
Will install mocha@7.2.0, which is a breaking change
node_modules/serialize-javascript
mocha 8.0.0 - 12.0.0-beta-2
Depends on vulnerable versions of serialize-javascript
node_modules/mocha
terser-webpack-plugin <=5.3.16
Depends on vulnerable versions of serialize-javascript
node_modules/terser-webpack-plugin
3 high severity vulnerabilities
```
Fixes: https://github.com/redhat-developer/vscode-openshift-tools/security/dependabot/122
Signed-off-by: Victor Rubezhny <vrubezhny@redhat.com>1 parent 3dc129a commit 1ea7d99
2 files changed
+314
-63
lines changed
0 commit comments