Closed
Description
patch-package
depends on semver@^5.6.0
, which is vulnerable to CVE-2022-25883. This can be fixed by upgrading to semver@7.5.3
or later.
Metadata
Metadata
Assignees
Labels
No labels
patch-package
depends on semver@^5.6.0
, which is vulnerable to CVE-2022-25883. This can be fixed by upgrading to semver@7.5.3
or later.