Skip to content

Vulnerabilities in the latest react-localize-redux #235

@johnwen84

Description

@johnwen84

Do you want to request a feature or report a bug?
bug

What is the current behavior?
npm i react-localize-redux@latest

5 high severity vulnerabilities

To address all issues (including breaking changes), run:
npm audit fix --force

If the current behavior is a bug, please provide the steps to reproduce and if possible a minimal demo of the problem. Your bug will get fixed much faster if we can run your code. Paste the link to your JSFiddle (https://jsfiddle.net/Luktwrdm/) or CodeSandbox (https://codesandbox.io/s/new) example below:
Just run,
npm i react-localize-redux@latest
npm will report 5 high severity vulnerabilities

What is the expected behavior?
We expect that no vulnerability should be reported
We can run "npm audit fix --force" to get rid of the vulnerabilities, but that will bring the version to 2.17.5, which causes package conflicts and maybe more other problems.

Which versions of react and react-localize-redux are you using?
"react": "^16.8.4",
"react-cookie": "^4.0.3",
"react-dom": "^16.8.4",
"react-localize-redux": "^3.5.3",
"react-redux": "^7.2.0",
"react-router-dom": "^5.2.0",
"redux": "^4.0.1",
"redux-thunk": "^2.3.0",

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions