Closed j0k3r closed 11 months ago
The version of fbjs integrated to prop-types@15.5.10 was pretty old (^0.8.9, latest is 3.0.4) and was requiring an old version of isomorphic-fetch (^2.1.1) which integrate node-fetch "^1.0.1" which has 2 CVEs (one low and one high):
fbjs
prop-types
^0.8.9
3.0.4
isomorphic-fetch
^2.1.1
node-fetch "^1.0.1"
I defined prop-types as ^15.6.2 which is the version where fbjs was removed. https://github.com/facebook/prop-types/blob/main/CHANGELOG.md#1562
^15.6.2
Closing as I removed prop-types as a dependency in v5.0.0.
The version of
fbjs
integrated toprop-types
@15.5.10 was pretty old (^0.8.9
, latest is3.0.4
) and was requiring an old version ofisomorphic-fetch
(^2.1.1
) which integratenode-fetch "^1.0.1"
which has 2 CVEs (one low and one high):I defined
prop-types
as^15.6.2
which is the version wherefbjs
was removed. https://github.com/facebook/prop-types/blob/main/CHANGELOG.md#1562