facebook / create-react-app

Set up a modern web app by running one command.
https://create-react-app.dev
MIT License
102.71k stars 26.85k forks source link

There are dependencies with vulnerabilities -- could you please update them #12325

Closed wnm3 closed 2 years ago

wnm3 commented 2 years ago

I believe from yarn why I am seeing these dependencies on older modules that have vulnerabilities:

image

Found "jake#async@0.9.2" info This module exists because "react-scripts#workbox-webpack-plugin#workbox-build#@surma#rollup-plugin-off-main-thread#ejs#jake" depends on it. info Disk size without dependencies: "120KB" info Disk size with unique dependencies: "120KB" info Disk size with transitive dependencies: "120KB" info Number of shared dependencies: 0

Found "svgo#css-what@3.4.2" info Reasons this module exists

Found "svgo#nth-check@1.0.2" info Reasons this module exists

wnm3 commented 2 years ago

Based on https://github.com/facebook/create-react-app/issues/11174 I will move react-scripts to dev dependencies