josephfrazier / reported-web

Web front-end for https://twitter.com/Reported_NYC: https://reported-web.herokuapp.com
https://reported-web.herokuapp.com
MIT License
10 stars 1 forks source link

Upgrade parse-dashboard so that ejs can be upgraded to fix vuln alert, see https://github.com/josephfrazier/reported-web/security/dependabot/118 #448

Closed josephfrazier closed 1 year ago

josephfrazier commented 1 year ago

Dependabot cannot update ejs to a non-vulnerable version

The latest possible version that can be installed is 2.7.4 because of the following conflicting dependencies:

parse-dashboard@1.4.3 requires ejs@^2.5.7 via a transitive dependency on webpack-bundle-analyzer@2.13.1
webpack-bundle-analyzer@3.9.0 requires ejs@^2.6.1

The earliest fixed version is 3.1.7.