-
-
Notifications
You must be signed in to change notification settings - Fork 27.1k
Closed
Description
Describe the bug
react-dev-tools has a dependency of [email protected] which is vulnerable
CVE-2020-28477
high severity
Vulnerable versions: < 8.0.1
Patched version: 8.0.1
Did you try recovering your dependencies?
Which terms did you search for in User Guide?
Environment
Steps to reproduce
Expected behavior
Getting the latest version of immer where the security issue has been fixed.
Actual behavior
Getting an outdated vulnerable dependency.
Reproducible demo
vegardok, konstantinblaesi, Mohron, jakemwood, stephanie-cherba and 13 morestruginskijstruginskij