truffle-box / react-box

Truffle, Webpack and React boilerplate.

Home Page:https://truffle-box.github.io/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[Vulnerability] Remote code execution vulnerability in react-scripts > react-dev-utils

njwest opened this issue · comments

There is a known remote code execution vulnerability in react-dev-utils, a dependency of react-scripts

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Remote Code Execution                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ react-dev-utils                                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ react-scripts                                                │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ react-scripts > react-dev-utils                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/695                       │
└───────────────┴──────────────────────────────────────────────────────────────┘
commented

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.