Skip to content

resolve: vulnerabilities#52

Merged
erolunal merged 2 commits into
mainfrom
vuln-updates
Mar 1, 2026
Merged

resolve: vulnerabilities#52
erolunal merged 2 commits into
mainfrom
vuln-updates

Conversation

@erolunal
Copy link
Copy Markdown
Contributor

@erolunal erolunal commented Mar 1, 2026

There is currently an open vulnerability for serialize-javacript a transitive dependency of @rollup/plugin-terser.

  • Downgrading @rollup/plugin-terser to 0.1.0 is not compatible with rollup 4.
  • We manually override the vulnerable library, a PR is currently in review for the rollup lib.

@erolunal erolunal requested a review from a team as a code owner March 1, 2026 18:11
Copy link
Copy Markdown

@jasonvanderslice jasonvanderslice left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for downgrade explanation!

@erolunal erolunal merged commit a847694 into main Mar 1, 2026
6 checks passed
@erolunal erolunal deleted the vuln-updates branch March 1, 2026 20:25
@erolunal erolunal mentioned this pull request Mar 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants