Closed janmashat closed 7 months ago
Hi! I'll try to check everything today. There are many libs on the client with vulnerabilities shown, but they're only used to build the production version, so they are not exploitable. More information here: https://github.com/facebook/create-react-app/issues/11174.
Great, thanks for the quick response!
I've made an update of all dependencies: 0 vulnerabilities in the root folder, 0 vulnerabilities in the server folder, vulnerabilities are shown in the client folder and we've verified that all of these packages are related specifically to the build process (so they can't be exploited).
Running
npm audit
reveals a number of vulnerable dependencies:Version:
Client:
Server: