uidaholib / inside_apps

0 stars 1 forks source link

security alert in yarn dependency #12

Open evanwill opened 4 years ago

evanwill commented 4 years ago

@kandersonko can you check this out, https://github.com/uidaholib/inside_apps/network/alert/yarn.lock/serialize-javascript/open

kandersonko commented 4 years ago

It seems like it is an issue with a dependency on Rollup JS (serialize-javascript). We are not using the "serialize-javascript" in the app. I will upgrade rollup to the latest version to see if the issue goes away. Thanks.