Replies: 2 comments 2 replies
-
I feel like there is an issue with the npm audit database for the recent advisories on React Router (data spoofing and cache poisoning)? The affected versions in the advisories are Does anyone know how we can resolve the npm audit false positives? |
Beta Was this translation helpful? Give feedback.
2 replies
-
Yeah this was a missed lower bound on the security advisory that was filed. We've since updated the advisory - it did not affect any versions prior to v7. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi! I just wanted to check if we could expect an "patch" on react-router-dom
5.3.4
related to the vulnerability:GHSA-cpj6-fhp6-mr6j
that was fixed in
7.5.2
.One of our applications is still using
5.3.4
and we have a plan to migrate to 7.x but it will result in some rewrite and it would have been nice to do that later on and not as part of a "security patch".... Maybe this vulnerability is not relevant for
5.3.4
?Regards Hans
Beta Was this translation helpful? Give feedback.
All reactions