ualbertalib / avalon

University of Alberta's Media Repository based on Avalon
Apache License 2.0
2 stars 2 forks source link

Build pipeline CVEs: @rails/webpacker transitive dependency postcss CVE-2021-23368 and is-svg CVE-2021-28092 #747

Closed jefferya closed 3 years ago

jefferya commented 3 years ago

JS webpacker tooling impacted by transitive dependency postcss CVE-2021-23368 and is-svg CVE-2021-28092. @rails/webpacker doesn't currently have a backport.

Scope:

Impact:

Todo: