davidroyer/vue2-editor

Update quill version to ^1.3.7

christianlmc opened this issue · 3 comments

Quill has a vulnerability on version 1.3.6. npm audit gives this output on the package:

quill  <=1.3.7
Severity: moderate
Cross-site Scripting in quill - https://github.com/advisories/GHSA-4943-9vgg-gr5r
fix available via `npm audit fix --force`
Will install vue2-editor@1.0.1, which is a breaking change
node_modules/quill
  vue2-editor  >=1.0.2
  Depends on vulnerable versions of quill
  node_modules/vue2-editor

This issue is stale because it has been open for 60 days with no activity.

This issue was closed because it has been inactive for 7 days since being marked as stale.

@davidroyer the issue is still a thing, it should be reopened