jaredpalmer / tsdx

Zero-config CLI for TypeScript package development
https://tsdx.io
MIT License
11.26k stars 508 forks source link

Update rollup-plugin-terser to fix vulnerability #797

Closed known-as-bmf closed 4 years ago

known-as-bmf commented 4 years ago

Current Behavior

rollup-plugin-terser v5.x has a dependency on serialize-javascript 2.x. This version of serialize-javascript includes an high severity security issue.

Expected behavior

No security issue.

Suggested solution(s)

Bump rollup-plugin-terser dependency to at least ^6.0.0.

Additional context

N/A

Your environment

TSDX 0.13.2

agilgur5 commented 4 years ago

Duplicate of https://github.com/formium/tsdx/pull/731#issuecomment-672246494