egoist / egoist/rollup-plugin-postcss
Vulnerability on version 4.0.0 related with is-svg
Open
- Dominant language
- JavaScript
- Stars
- 689
- Forks
- 210
- PR merge metrics
- No merged PRs in 30d
Description
I am using `rollup-plugin-postcss` on my project and the dependabot found this vuln:
```
Dependabot cannot update is-svg to a non-vulnerable version
The latest possible version that can be installed is 3.0.0 because of the following conflicting dependency:
rollup-plugin-postcss@4.0.0 requires is-svg@^3.0.0 via a transitive dependency on postcss-svgo@4.0.2
The earliest fixed version is 4.2.2.
View logs or learn more about troubleshooting Dependabot errors.
```
Are you going to fix that? Please!
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.