facebookarchive / draft-js

A React framework for building text editors.
https://draftjs.org/
MIT License
22.56k stars 2.64k forks source link

Package vulnerability update required. (fbjs > cross-fetch) #3147

Open WilliamHolmes opened 2 years ago

WilliamHolmes commented 2 years ago

Do you want to request a feature or report a bug?

Security BUG

What is the current behavior?

cross-fetch Needs to be updated as the current version has a vulnerability

└─┬ draft-js@0.11.7
  └─┬ fbjs@2.0.0
    └── cross-fetch@3.1.4

https://snyk.io/advisor/npm-package/cross-fetch https://nvd.nist.gov/vuln/detail/CVE-2022-1365