Skip to content

fix: bump loader-utils from 2.0.2 to 2.0.3 (CVE-2022-37601, GHSA-76p3-8jx3-jpfq)#4

Open
kiloconnect-development[bot] wants to merge 1 commit into
mainfrom
security-remediation/loader-utils-ghsa-76p3-8jx3-jpfq/0bd474f677-1
Open

fix: bump loader-utils from 2.0.2 to 2.0.3 (CVE-2022-37601, GHSA-76p3-8jx3-jpfq)#4
kiloconnect-development[bot] wants to merge 1 commit into
mainfrom
security-remediation/loader-utils-ghsa-76p3-8jx3-jpfq/0bd474f677-1

Conversation

@kiloconnect-development

Copy link
Copy Markdown

Security Remediation

Bumps loader-utils from 2.0.2 to 2.0.3 to fix prototype pollution vulnerability.

Changes

  • Updated loader-utils version in package.json from 2.0.2 to 2.0.3
  • Updated package-lock.json to reflect the patched version

Kilo Finding

http://localhost:3000/security-agent/findings?findingId=0bd474f6-772f-4855-8556-99ae79a29999

Fixes prototype pollution vulnerability GHSA-76p3-8jx3-jpfq in
loader-utils >= 2.0.0, < 2.0.3. Patched in 2.0.3.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants