Snyk has created this PR to upgrade css-loader from 5.2.6 to 5.2.7.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1 version ahead of your current version.
The recommended version was released 6 months ago, on 2021-07-13.
Snyk has created this PR to upgrade css-loader from 5.2.6 to 5.2.7.
The recommended version fixes:
SNYK-JS-NANOID-2332193
Why? Proof of Concept exploit, Recently disclosed, CVSS 4
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: css-loader
5.2.7 (2021-07-13)
Bug Fixes
[@ import](https://snyk.io/redirect/github/import)
(bb76fe4)5.2.6 (2021-05-24)
Bug Fixes
Commit messages
Package name: css-loader
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:![](https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIxOWU2MWRjYi1hYjE5LTRhNWYtOGY0Ni1hZjM5NDIzOWRjNWYiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjE5ZTYxZGNiLWFiMTktNGE1Zi04ZjQ2LWFmMzk0MjM5ZGM1ZiJ9fQ==)
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs