segmentio / evergreen

🌲 Evergreen React UI Framework by Segment
https://evergreen.segment.com
MIT License
12.38k stars 830 forks source link

security: v6.13.1 dependency contains vulnerable `node-fetch` version #1552

Closed plimbear closed 1 year ago

plimbear commented 1 year ago

I tried fixing by downgrading the evergreen-ui as well as node-fetch but still there is no change reflecting.

Screenshot 2022-11-23 at 10 46 12 PM

Can someone from the team suggest me a fix for this security bug?

brandongregoryscott commented 1 year ago

Please see #1304