-
-
Notifications
You must be signed in to change notification settings - Fork 26.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Latest version of react-dev-utils using immer v8.0.1 #11660
Comments
ran into the same issue and reported by security scan. Can we fix this? immer 8.0.6 has a vulnerability. |
This looks like it was addressed 2 months ago and merged into the main branch but without publishing it to npm since react-dev-utils@11.0.4 from 9 months ago. |
when are they planning to publish the newer version to npm ? |
Btw. the used |
This has been reported 13 days ago and it is still labeled as |
Would also love to see this get published soon, please and thank you! |
Having the same |
Same here |
same issue here |
same |
same, but got it fixed with npm and this workaround for now (package.json):
it is bad I know but it is saving me some of my precious time :-) |
Thank you was facing issues trying to use this fix with npm but with yarn it was working fine not sure why. |
same |
is there any ETA? |
Any update? |
CRA was updated to v5 yesterday (github.com/facebook/create-react-app/releases/tag/v5.0.0). So it should be fixed now. |
when I used react-dev-utils , the version of immer which I got is v8.0.1 instead of v9.0.6, immer of version 8.0.1 which has type confusion vulnerability , it is effecting my work kindly resolve this issue.
The text was updated successfully, but these errors were encountered: