-
Notifications
You must be signed in to change notification settings - Fork 670
Open
Description
Summary
various rushstack projects have a vulnerable version of ajv. We need to bump the version of ajv anywhere to 8.18.0
ajv has ReDoS when using $data option
GHSA-2g4f-4pwh-qvx6
Impacted projects include:
- @rushstack/eslint-config
- @rushstack/eslint-plugin
- @rushstack/eslint-plugin-packlets
- @rushstack/eslint-plugin-security
- @rushstack/node-core-library
- @rushstack/heft
- @rushstack/node-core-library
- @rushstack/set-webpack-public-path-plugin
- @rushstack/terminal
- @rushstack/webpack5-localization-plugin
- @rushstack/ts-command-line
- @rushstack/heft-sass-plugin
- @rushstack/typings-generator
- @rushstack/debug-certificate-manager
- @rushstack/heft-dev-cert-plugin
- @rushstack/heft-webpack5-plugin
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Needs triage