Skip to content

react-scripts is using postcss@^7.0.35 which has security vulnerability #13423

@biaoqiu

Description

@biaoqiu

[email protected] requires postcss@^7.0.35 via a transitive dependency on [email protected]

I see the latest version of resolve-url-loader is 5.x, and it depends on [email protected]. So can we update resolve-url-loader to a non-vulnerable version? Thank you!

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions