egoist / egoist/rollup-plugin-postcss

Vulnerability on version 4.0.0 related with is-svg

Open
#363 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
689
Forks
210
PR merge metrics
No merged PRs in 30d

Description

I am using `rollup-plugin-postcss` on my project and the dependabot found this vuln:

```
Dependabot cannot update is-svg to a non-vulnerable version
The latest possible version that can be installed is 3.0.0 because of the following conflicting dependency:

rollup-plugin-postcss@4.0.0 requires is-svg@^3.0.0 via a transitive dependency on postcss-svgo@4.0.2
The earliest fixed version is 4.2.2.

View logs or learn more about troubleshooting Dependabot errors.
```

Are you going to fix that? Please!

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.