trivago / melody

Melody is a library for building JavaScript web applications.
https://melody.js.org
Apache License 2.0
215 stars 39 forks source link

CVE-2023-45133 - melody-extension-core > babel-template > babel-traverse #195

Open Levdbas opened 5 months ago

Levdbas commented 5 months ago

Explain the problem

There is a vulnerability in babal traverse that is fixed in babel template 7.24.0. I know that this repo is not really maintained by Trivago anymore but it is not archived either. Would you be so kind to audit the packages used in this monorepo and update them where possible?

https://github.com/advisories/GHSA-67hx-6x53-jw92

@ayusharma , @twbartel

Levdbas commented 3 weeks ago

Hi @ayusharma and @twbartel,

I would love to see these packages getting some bumps in the required packages and then release new versions. If would be of great help for other packages depending on your code.

Let me know if I can be of help