bevacqua / dragula

:ok_hand: Drag and drop so simple it hurts
https://bevacqua.github.io/dragula/
MIT License
22.08k stars 1.97k forks source link

fix(sec): upgrade uglify-js to 3.14.3 #702

Closed pen4 closed 1 year ago

pen4 commented 1 year ago

What happened?

There are 1 security vulnerabilities found in uglify-js 3.11.0

What did I do?

Upgrade uglify-js from 3.11.0 to 3.14.3 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS Signed-off-by:pen4948453219@qq.com