liuweiGL/vite-plugin-mkcert

Package requires a security update

plamber opened this issue ยท 2 comments

Describe the bug

We recently upgraded to the latest version 1.17.0 and we receive a high severity vulnerability caused by axios.

Server-Side Request Forgery in axios - GHSA-8hc4-vh64-cxmj

image

Would it be possible to update the package with the hotfixes?

Thank you

This advisory says that a vulnerability still exists and isn't resolved until axios 1.7.3

GHSA-8hc4-vh64-cxmj

๐ŸŽ‰ This issue has been resolved in version 1.17.6 ๐ŸŽ‰

The release is available on:

Your semantic-release bot ๐Ÿ“ฆ๐Ÿš€