Closed maxdeichmann closed 1 week ago
Hey! These lower level dependencies typically aren't pinned, which means that you should be able to run npm update
or npm audit fix
.
If you install Tailwind CSS v3 from scratch, you'll notice that cross-spawn@7.0.5
is already installed (at the time of writing this) which is also the version suggested by the security report.
That said, the pnpm-lock.yaml
file is from the Tailwind CSS v4 codebase (next
branch), not the v3 codebase (main
branch). These lock files are not published to npm, so the update commands I mentioned earlier should just work.
Hope this helps!
What version of Tailwind CSS are you using?
For example: tailwindcss 3.4.14
What build tool (or framework if it abstracts the build tool) are you using?
For example: next 14.2.15
What version of Node.js are you using?
For example: v12.0.0
What browser are you using?
For example: Chrome
What operating system are you using?
For example: macOS
Reproduction URL
Describe your issue
We are faced with the SNYK-JS-CROSSSPAWN-8303230 vulnerability which occurs in cross-spawn < 7.0.5. Can you please upgrade the dependencies on your end?
https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230