Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nested dependency es5-ext has a security vulnerability (low) and needs update #1474

Open
fredericpellin opened this issue Feb 27, 2024 · 1 comment

Comments

@fredericpellin
Copy link

es5-ext has vulnerability CVE-2024-27088

update has been done on es5-ext

Is it possible to update sequelize to use 0.10.63 of es5-ext ?

@fredericpellin fredericpellin changed the title nested dependency es5-ext has a security vulnerability and needs update nested dependency es5-ext has a security vulnerability (low) and needs update Feb 27, 2024
@WikiRik
Copy link
Member

WikiRik commented Feb 27, 2024

As far as I can see on the lockfile of our latest release (6.6.2), our dependencies do not have es5-ext pinned so if you refresh your lockfile it should be able to update to 0.10.63 already.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants