Use of Insecure Tinycolor within vscode-mssql #20210
Answered
by
kburtram
adamreisberg-acn
asked this question in
Q&A
-
The Lines 83 to 85 in ea10207 Given the following supply chain attack as noted here... ... plus the recommendations in the following issue, as quoted below
... there are a few questions:
|
Beta Was this translation helpful? Give feedback.
Answered by
kburtram
Sep 25, 2025
Replies: 1 comment
-
We bumped to 4.2.0 with #20230. The yarn.lock was pinned to 4.1.0 so there should not have been an impacted version of tinycolor in the supply chain as far as I know. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
kburtram
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We bumped to 4.2.0 with #20230. The yarn.lock was pinned to 4.1.0 so there should not have been an impacted version of tinycolor in the supply chain as far as I know.