You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
this vulnerability seems completely irrelevant here since svgo in this context is not used on arbitrary user data. it is only used on the SVG files that you add to your project, and most likely you won't try to DoS yourself... 😅
this vulnerability seems completely irrelevant here since svgo in this context is not used on arbitrary user data. it is only used on the SVG files that you add to your project, and most likely you won't try to DoS yourself... 😅
my boss doesn't care, he sees a vulnerability in a snyk report - demands to remove the dependency
🐞 Bug Report
Describe the bug
[email protected]
, a transient dependency of[email protected]
, has an Inefficient Regular Expression Complexity vulnerability.[email protected]
is a dependency of[email protected]
.Expected behavior
There should not be security vulnerability.
Possible Solution
Update
svgo
to v3.0.2 which uses[email protected]
as a transient dependency.The text was updated successfully, but these errors were encountered: