magr0s / vue-scrollmagic

Vue.js plugin
MIT License
72 stars 24 forks source link

Depends on vulnerable version of gsap (gsap<3.6.0) #22

Open 54mu3l opened 3 years ago

54mu3l commented 3 years ago

npm audit lets us know:

There is a prototype pollution vulnerability in gsap which affects all versions before 3.6.0.

https://www.npmjs.com/advisories/1608

Is there a new version of vue-scrollmagic planned to fix this dependency?

Thank you!

samuelsennev commented 1 year ago

Same problem here...

Solved by uninstalling vue-scrollmagic and installing the default scrollmagic package