-
-
Notifications
You must be signed in to change notification settings - Fork 626
Closed
Description
- Rollup Plugin Name: @rollup/plugin-commonjs
- Rollup Plugin Version: 25.0.7
@rollup/plugin-commonjs depends on inflight and it is vulnerable.
https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
@rollup/plugin-commonjs@25.0.7
└─┬ glob@8.1.0
└── inflight@1.0.6
Expected Behavior
@rollup/plugin-commonjs package doesn't depend on inflight package
Actual Behavior
@rollup/plugin-commonjs package depends on inflight package
Additional Information
To fix the vulnerability need to update glob package to version 10+
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels