We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
jade "~1.11.0" in /server/package.json is dependent on constantinople 3.0.2 jade was last update 8 years ago. Replaced by pug
constantinople 3.0.2 has a sandbox bypass vulnerability leading to arbitrary code execution. The earliest fixed version of constantinople is 3.1.1
https://osv.dev/vulnerability/GHSA-4vmm-mhcq-4x9j
The text was updated successfully, but these errors were encountered:
jade also creates a dependency on critically vulnerable version 2.2.5 of uglify-js via transformers 2.1.0
Sorry, something went wrong.
It means 200+ projects are vulnerable to rce
No branches or pull requests
jade "~1.11.0" in /server/package.json is dependent on constantinople 3.0.2
jade was last update 8 years ago.
Replaced by pug
constantinople 3.0.2 has a sandbox bypass vulnerability leading to arbitrary code execution.
The earliest fixed version of constantinople is 3.1.1
https://osv.dev/vulnerability/GHSA-4vmm-mhcq-4x9j
The text was updated successfully, but these errors were encountered: