Skip to content

update immer to 8.0.1 to address vulnerability#10412

Merged
iansu merged 1 commit into
react:masterfrom
wclem4:immer-update
Feb 22, 2021
Merged

update immer to 8.0.1 to address vulnerability#10412
iansu merged 1 commit into
react:masterfrom
wclem4:immer-update

Conversation

@wclem4
Copy link
Copy Markdown
Contributor

@wclem4 wclem4 commented Jan 20, 2021

Resolves #10411

Bumps immer version to 8.0.1 to address the prototype pollution
vulnerability with the current 7.0.9 version.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

react-dev-utils uses a vulnerable version of immer as a dependency