semantic-release / npm

:ship: semantic-release plugin to publish a npm package
MIT License
244 stars 114 forks source link

CVE-2023-42282 #756

Closed bpneal closed 7 months ago

bpneal commented 7 months ago

Please can you bump your version of npm (in the package-lock) to mitigate its use of ip which contains this security exception. https://nvd.nist.gov/vuln/detail/CVE-2023-42282

travi commented 7 months ago

See https://github.com/semantic-release/semantic-release/issues/3202#issuecomment-1954911410