Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CLI] upgrade esbuild to 0.25.0 (GHSA-67mh-4wv8-2f99) #1762

Open
madebyfabian opened this issue Mar 6, 2025 · 1 comment
Open

[CLI] upgrade esbuild to 0.25.0 (GHSA-67mh-4wv8-2f99) #1762

madebyfabian opened this issue Mar 6, 2025 · 1 comment

Comments

@madebyfabian
Copy link
Contributor

madebyfabian commented Mar 6, 2025

I got a dependabot security alert, that the trigger.dev npm cli package uses [email protected], which has a vulnerability (see GHSA-67mh-4wv8-2f99)

Even though it's a CLI and (in my understanding) will not be facing network, I think it would be good to still upgrade esbuild to 0.25.0 or higher.

If you feel this is not important, you can of course close this. Just wanted to bring this to attention :)

@madebyfabian madebyfabian changed the title [CLI] upgrade eslint to 0.25.0 (GHSA-67mh-4wv8-2f99) [CLI] upgrade esbuild to 0.25.0 (GHSA-67mh-4wv8-2f99) Mar 6, 2025
@Rudra-Sankha-Sinhamahapatra

@madebyfabian Do we need that because i was trying to upgrade it and it shows unmet peer dependencies react18

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants