data-dot-all / dataall

A modern data marketplace that makes collaboration among diverse users (like business, analysts and engineers) easier, increasing efficiency and agility in data projects on AWS.
https://data-dot-all.github.io/dataall/
Apache License 2.0
229 stars 82 forks source link

Frontend package vulnerabilities with high Severity #1563

Open anisubhra-syncron opened 1 week ago

anisubhra-syncron commented 1 week ago

While deploying our app based on v2.6 upgrade we have found out that few packages are showing vulnerabilities with high severity. Can you please comment on these listed 5 vulnerabilities:

image

dlpzx commented 5 days ago

Hi @anisubhra-syncron thanks for opening an issue. All those vulnerabilities are fixed in the main branch. Here are the links to all dependencies upgrade pull requests since 2.6.0 release. We will soon release 2.7.0 which will contain these upgrades and will resolve the errors you are seeing in npm audit. We can sync offline on the best way to proceed until 2.7 is released