Skip to content

Update json5 to 2.2.3 to fix CVE-2022-46175 - #53

Open
andreas-schwab-swx wants to merge 1 commit into
dnut:masterfrom
andreas-schwab-swx:fix/update-json5
Open

Update json5 to 2.2.3 to fix CVE-2022-46175#53
andreas-schwab-swx wants to merge 1 commit into
dnut:masterfrom
andreas-schwab-swx:fix/update-json5

Conversation

@andreas-schwab-swx

Copy link
Copy Markdown

json5 versions before 2.2.2 are vulnerable to prototype pollution via the parse method (CVE-2022-46175). Update the dependency and refresh the lockfile.

json5 versions before 2.2.2 are vulnerable to prototype pollution via
the parse method (CVE-2022-46175). Update the dependency and refresh
the lockfile.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant