-
Notifications
You must be signed in to change notification settings - Fork 13.3k
Closed
Labels
BugA bug in TypeScriptA bug in TypeScriptFix AvailableA PR has been opened for this issueA PR has been opened for this issue
Milestone
Description
We will need to only allow package names for loaded editor plugin names, to mitigate issues described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1639
We'll be porting this to the following TypeScript versions:
- 3.1.7
- 3.7.6
- 3.9.8
- 4.0.6
- 4.1.4
- 4.2+
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
BugA bug in TypeScriptA bug in TypeScriptFix AvailableA PR has been opened for this issueA PR has been opened for this issue