Skip to content

Dependencies using vulnerable postcss version #6

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
jeroentvb opened this issue Feb 27, 2022 · 0 comments
Closed

Dependencies using vulnerable postcss version #6

jeroentvb opened this issue Feb 27, 2022 · 0 comments

Comments

@jeroentvb
Copy link
Contributor

spicetify-creator is using typescript-plugin-css-modules, which has dependencies using on a vulnerable version of postcss. For example postcss-filter-plugins depends on version 6 of postcss, while the current is version 8.

There is an open issue on typescript-plugin-css-modules about this issue located here. But doesn't look like anything is being done about it.
The issue has been created the 7th of january this year, while the last release was the 5th of june 2021.

Is there anything to be done to resolve this, or do we wait for the dependencies to update (which will take a while, or may not happen at all).

FlafyDev added a commit that referenced this issue Jun 29, 2022
chore(deps): update deps & remove unused & vulnerable dependency - fixes #6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant