bholloway / resolve-url-loader

Webpack loader that resolves relative paths in url() statements based on the original source file
563 stars 71 forks source link

postcss Denial of Service #203

Closed TerrenceBerg closed 3 years ago

TerrenceBerg commented 3 years ago

I have a problem with "postcss": "^7.0.35", When I run npm audit this is what I get. postcss 7.0.0 - 8.2.9 Severity: moderate Regular Expression Denial of Service - https://npmjs.com/advisories/1693 fix available via npm audit fix --force Will install resolve-url-loader@2.3.2, which is a breaking change node_modules/resolve-url-loader/node_modules/postcss resolve-url-loader 3.0.0-alpha.1 - 4.0.0 Depends on vulnerable versions of postcss node_modules/resolve-url-loader

bholloway commented 3 years ago

Please refer to #198 for solutions

TerrenceBerg commented 3 years ago

Thank you Ben!

On May 20, 2021, at 3:03 PM, Ben Holloway @.***> wrote:

Please refer to #198 https://github.com/bholloway/resolve-url-loader/issues/198 for solutions

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/bholloway/resolve-url-loader/issues/203#issuecomment-845506532, or unsubscribe https://github.com/notifications/unsubscribe-auth/ACC5T6OQQETOT267MZYUSPTTOWBKZANCNFSM45HRKLUA.