Closed
Description
vue loader version needs to be bumped to at least v16.0.0 as per this report GHSA-76p3-8jx3-jpfq
# npm audit report
loader-utils <2.0.3
Severity: critical
Prototype pollution in webpack loader-utils - https://github.com/advisories/GHSA-76p3-8jx3-jpfq
No fix available
node_modules/vue-loader/node_modules/loader-utils
node_modules/vue-style-loader/node_modules/loader-utils
vue-loader 2.0.0 - 16.0.0-rc.2
Depends on vulnerable versions of loader-utils
Depends on vulnerable versions of vue-style-loader
node_modules/vue-loader
@nextcloud/webpack-vue-config *
Depends on vulnerable versions of vue-loader
node_modules/@nextcloud/webpack-vue-config
vue-style-loader *
Depends on vulnerable versions of loader-utils
node_modules/vue-style-loader
4 critical severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Metadata
Metadata
Assignees
Labels
No labels