vuejs / vue-cli

🛠️ webpack-based tooling for Vue.js Development
https://cli.vuejs.org/
MIT License
29.76k stars 6.33k forks source link

vulnerabilities with got, git-clone, and http-cache-semantics #7455

Closed Tri-Vi closed 5 months ago

Tri-Vi commented 6 months ago

Version

5.0.8

Environment info

Dev and Production

Steps to reproduce

npm audit

What is expected?

0 vunerabilitty

What is actually happening?

I am writing to report vulnerabilities in dependencies of Vue CLI that have been identified through npm audit. These vulnerabilities pose a risk to the security of Vue CLI and projects using it.

git-clone:

got:

http-cache-semantics:


I kindly request that these vulnerabilities be addressed in the next release of Vue CLI

Tri-Vi commented 5 months ago

Closing this ticket as resolved