Skip to content

Upgrade ESLint dependencies to fix "high severity security vulnerabilities" #8663

Closed
@phoqe

Description

@phoqe

Is your proposal related to a problem?

When creating a new app with the default template it starts with two high severity security vulnerabilities in two of ESLints dependencies: acorn and minimist.

The releases 1.8.3 and lower of svjsl (JSLib-npm) are vulnerable, but only if installed in a developer environment. A patch has been released (v1.8.4) which fixes these vulnerabilities.

Identifiers:
CVE-2020-7598
SNYK-JS-ACORN-559469

Describe the solution you'd like

Upgrade minimist to version 1.2.2 or later.
Upgrade acorn to version 7.1.1 or later.

Describe alternatives you've considered

N/A

Additional context

Screen Shot 2020-03-16 at 10 42 11 AM

Screen Shot 2020-03-16 at 10 42 22 AM

Screen Shot 2020-03-16 at 10 42 34 AM

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions