Skip to content

Allow usage of serialize-javascript@^7.0.3#817

Closed
cedric-anne wants to merge 1 commit intowebpack:mainfrom
cedric-anne:patch-1
Closed

Allow usage of serialize-javascript@^7.0.3#817
cedric-anne wants to merge 1 commit intowebpack:mainfrom
cedric-anne:patch-1

Conversation

@cedric-anne
Copy link

Summary

serialize-javascript < 7.0.3 is vulnerable, see GHSA-5c6j-r48x-rmvq.

Since there is no breaking change between serialize-javascript v6 and v7, except the supported version of node, it seems safe to allow the usage of the v7.

What kind of change does this PR introduce?

It permit use a non-vulnerable version of a dependency.

Did you add tests for your changes?

No, existing tests should already cover the changes.

Does this PR introduce a breaking change?

No.

Use of AI

Never.

@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Mar 2, 2026

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: cedric-anne / name: Cédric Anne (6fbfe9c)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant