Skip to content

Conversation

VanessaHenderson
Copy link

What kind of change does this PR introduce? (check at least one)

  • Bugfix
  • Feature
  • Code style update
  • Refactor
  • Docs
  • Underlying tools
  • Other, please describe: Upgrade dependencies to fix a transitive vulnerability

Does this PR introduce a breaking change? (check one)

  • Yes
  • No

Other information:
All the tests ran fine, its a minor version upgrade from 4.1.0 to 4.7.0. Alternatively the webpack-dev-server library can be updated to 4.1.1 which is the first version with the fixed transitive vulnerability in it. Will probably want to be ported to a 4.x version of vue/cli-service as well.
Vulnerability information: GHSA-whgm-jr23-g3j9
Webpack-dev-server commit that fixed the vulnerability there: webpack/webpack-dev-server@36fd214

@VanessaHenderson
Copy link
Author

@sodatea Any chance we can get this merged to fix a vulnerability? 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant