Skip to content

Package depends on vulnerable version of semver #67

@arstulke

Description

@arstulke

Version @alma-cdk/openapix@0.0.51 (currently latest version) includes semver@7.3.8 which is a vulnerable version as bundled dependency. The semver vulnerability has a severity of high.

I tried updating it quickly but it requires updating projen aswell. Projen installs a newer version of JSII which requires some larger code changes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions