Skip to content

Conversation

kdv24
Copy link

@kdv24 kdv24 commented Jun 4, 2021

Currently ejs-webpack-loader is dependent on a package, merge, with a high security vulnerability. This PR simply updates the merge package to the recommended version.

@dalarson
Copy link

dalarson commented Mar 2, 2022

Bumping this thread - Also dealing with need to mitigate security vulnerability in merge. Can we merge this update?

@rorkflash rorkflash merged commit a0c88ed into rorkflash:2.x Mar 5, 2022
@dalarson
Copy link

dalarson commented Mar 7, 2022

Hi, can we get a release with this change pushed to npm public registry?

@dalarson
Copy link

Hi, can we get a release with this change pushed to npm public registry?

Bumping this thread. We cannot consume these changes unless a new release is published to public npm registry. Can we please get a release pushed? Thanks in advance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants