ember-cli / ember-cli/ember-cli

Security vulnerability with `braces` package

Open
#10,473 5 comments 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
3.2k
Forks
1.2k
Avg merge
1d 11h
Merged PRs (30d)
8

Description

We're running into security vulnerabilities from <`v3.0.3` versions of the `braces` package. Checking out our dependency chain, it looks like it should be fixed if
- `broccoli` updates `sane` (there already exists a [PR](https://github.com/broccolijs/broccoli/pull/506) to do so) and then `ember-cli` pulls in the update.
- `ember-cli-dependency-checker` updates `find-yarn-workspace-root` to `v2.0.0`.
![Screenshot 2024-06-20 at 3 01 53 PM](https://github.com/ember-cli/ember-cli/assets/17748358/4aa36ae6-4a56-49f7-8ab3-6efbdfdf948e)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.