The jQuery code included in the repo is vulnerable one and whomever picks it up, will be alerted about vunerability, even if the jQuery files are not really used in production.
dom-to-image library has jQuery in version "~2.1.3" as an dependency, which is vulnerable to:
The jQuery code included in the repo is vulnerable one and whomever picks it up, will be alerted about vunerability, even if the jQuery files are not really used in production.
dom-to-image
library hasjQuery
in version "~2.1.3" as an dependency, which is vulnerable to: