potential security vulnerability when bundling via an outdated version of [email protected] etc. #2386
Description
Hi,
First, this is a great lib!
Second this is perhaps not the place to report it, please feel free to close the issue, but:
There is a quite complex dependency chain on static-eval in the package.json which is affected by this security vulnerability:
https://nodesecurity.io/advisories/548
[email protected] › [email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected]
There is already an issue entered for glslify at glslify/glslify#106
We would then need to move up in the dependency chain to the other components
Would also be good to have a security badge with:
snyk: https://github.com/snyk/snyk#badge
or
nsp: see https://github.com/dwyl/repo-badges
Thx
Alex