commercetools / commercetools/typescript-dev-utilities

Vulnerable to CVE-2026-8657

Open
#59 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

The `jsondiffpatch` dependency is vulnerable to https://www.cve.org/CVERecord?id=CVE-2026-8657 and flagged as high priority in our Snyk scans. It's fixed in `0.7.6`. I appreciate that `jsondiffpatch` is ESM only after `0.5` which will make the change non-trivial.

Thanks.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.