Skip to content

Update node_module vulnerable transitive dependencies "nth-check" and "trim". #6394

@VictorGFM

Description

@VictorGFM

Have you read the Contributing Guidelines on issues?

Prerequisites

  • I'm using the latest version of Docusaurus.
  • I have tried the npm run clear or yarn clear command.
  • I have tried rm -rf node_modules yarn.lock package-lock.json and re-installing packages.
  • I have tried creating a repro with https://new.docusaurus.io.
  • I have read the console error message carefully (if applicable).

Description

The current version of docusaurus (2.0.0-beta.14) relies on some transitive dependencies that are vulnerable. The GitHub already reported the CVEs related to those dependencies but the docusaurus still using them, so would be good if they could get upgraded.

Steps to reproduce

Verify the dependencies described in the description.

Expected behavior

Use the updated versions of the described dependencies.

Actual behavior

The versions of the described dependencies are vulnerable.

Your environment

  • Public source code:
  • Public site URL:
  • Docusaurus version used:
  • Environment name and version (e.g. Chrome 89, Node.js 16.4):
  • Operating system and version (e.g. Ubuntu 20.04.2 LTS):

Reproducible demo

No response

Self-service

  • I'd be willing to fix this bug myself.

Metadata

Metadata

Assignees

No one assigned

    Labels

    closed: please-fix-this-cveThis issue is asking for fixing a CVE in a build-only dep which doesn't pose any real threat.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions