Skip to content

Security: serialize-javascript@6.0.2 vulnerable (GHSA-5c6j-r48x-rmvq) – upgrade to 7.0.3 breaks tests #422

@runephilosof-abtion

Description

@runephilosof-abtion

GHSA advisory link : GHSA-76p7-773f-r4q5
Current dependency: 6.0.2
Vulnerable range: ≤ 7.0.2
Fixed in: 7.0.3
Attempted upgrade → node 18 CI fails #421 (ReferenceError: crypto is not defined)
i would like to Request maintainer guidance.

Is the current usage of serialize-javascript within this plugin actually exploitable in practice?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions