fontello / svg2ttf

SVG -> TTF font convertor
MIT License
518 stars 79 forks source link

Auditing webfont v11.2.20 which uses svg2ttf v6.02 reveals a moderate vulnerability in xmldom #115

Closed PrashantChittiZS closed 3 years ago

PrashantChittiZS commented 3 years ago

Running npm audit while using webfont v11.2.20, reveals a vulnerability in xmldom, which is internally used by svg2ttf v6.0.2. The vulnerability is moderate in severity and is said to be fixed in v0.7.0 of xmldom.

Here is the screenshot for reference: image

puzrin commented 3 years ago

Nobody cares.