Skip to content

@docusaurus/code latest version used [email protected], which has Security Vulnerability #11256

Open
@naico-wang

Description

@naico-wang

Have you read the Contributing Guidelines on issues?

Prerequisites

  • I'm using the latest version of Docusaurus.
  • I have tried the npm run clear or yarn clear command.
  • I have tried rm -rf node_modules yarn.lock package-lock.json and re-installing packages.
  • I have tried creating a repro with https://new.docusaurus.io.
  • I have read the console error message carefully (if applicable).

Description

Security Vulnerability found by Trivy:

Image

Of course we can override the reference, but can we fix this officially?

Thanks.

Reproducible demo

No response

Steps to reproduce

  1. npm ls webpack-dev-server
  2. find the result

Expected behavior

Use the version which is higher than 5.2.1

Actual behavior

No functional affect, but for the security issue.

Trivy report shows the vulnerability

Your environment

  • Public source code:
  • Public site URL:
  • Docusaurus version used:
  • Environment name and version (e.g. Chrome 89, Node.js 16.4):
  • Operating system and version (e.g. Ubuntu 20.04.2 LTS):

Self-service

  • I'd be willing to fix this bug myself.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugAn error in the Docusaurus core causing instability or issues with its executionstatus: needs triageThis issue has not been triaged by maintainers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions