Skip to content

Remove ember-auto-import 1.12.1 DependencyTrack #11730

@gabrieltrita

Description

@gabrieltrita

Problem Statement

A security issue was detected in versions of ember-auto-import lower than 1.12.2, as it uses babel-traverse:6.26.0, would it be possible to remove the dependency on ember-auto-import 1.12.1?

Refs:

GHSA-67hx-6x53-jw92

Dependency Tree

ember-auto-import:1.12.2
ember-cli-babel:6.18.0
broccoli-babel-transpiler:6.5.1
babel-core:6.26.3
babel-traverse:6.26.0

Solution Brainstorm

Remove ember-auto-import 1.12.1:
https://github.com/getsentry/sentry-javascript/blob/d2d2e0af05bd1ab2a3b296ad3ebb976285775193/packages/ember/package.json#L39C5-L39C46

Metadata

Metadata

Assignees

No one assigned

    Projects

    Status

    Waiting for: Product Owner

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions