You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependency cwebp-bin was upgraded to 6.0.0 on May 29th, but a new version of this library was not released, so upstream dependencies are flagging this for an npm security audit.
The text was updated successfully, but these errors were encountered:
A new release that allows cwebp-bin to be >= 6.1.2 would be super useful.
Prior to that version cwebp-bin depends on the seemingly abandoned logalot, which pulls in a hilariously large number of outdated dependencies. Including (eventually) trim-newlines, which has a DOS vulnerability: GHSA-7p7h-4mm5-852v
Dependency cwebp-bin was upgraded to 6.0.0 on May 29th, but a new version of this library was not released, so upstream dependencies are flagging this for an npm security audit.
The text was updated successfully, but these errors were encountered: