sasstools / scss-tokenizer

A tokenzier for Sass' SCSS syntax
MIT License
24 stars 22 forks source link

jQuery Vulnerability in jsbase-64 #37

Open neryb opened 3 years ago

neryb commented 3 years ago

The version of jsbase-64 being used has a medium risk vulnerability being flagged by Whitesource: https://github.com/sasstools/scss-tokenizer/blob/b55257baa54197e7dae8085184cad7948fea0796/package.json#L34

Vulnerability: https://github.com/advisories/GHSA-gxr4-xjj5-5px2

Resolution: Update jsbase-64 to version 3.5.2 as the vulnerability was addressed here: https://github.com/dankogai/js-base64/commit/1f2403588c17ece254d3045e52ac89f1d74097ea