Any chance the security fix will get backported to [email protected]? We're still on [email protected] yet which relies on this version range. Here is the respective issue in webpack-dev-server. Thanks for your consideration.
````
=== npm audit security report ===
SEMVER WARNING: Recommended action is a potentially breaking change
โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ High โ Missing Origin Validation โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Package โ webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Dependency of โ react-scripts โ
โโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Path โ react-scripts > webpack-dev-server โ
โโโโโโโโโโโโโโโโโผโ๏ฟฝ๏ฟฝ๏ฟฝโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ More info โ https://nodesecurity.io/advisories/725 โ
โโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
````
It sounds like they are not going to backport the fix. I'm closing this as I don't think there's anything we can do about it.
"Steal a developer's source code" -- the source code is public anyways during deployment, this should really be a low/medium security report.
I am getting the same error using the latest version of CRA 2.1.2. My npm audit says the vulnerability is patched in [email protected] and react-scripts uses 3.1.9.
guys an update on this is appreciated! webpack-dev-server is not backporting the fix, one possible resolution is to update react to depend on newer version.
Most helpful comment
guys an update on this is appreciated! webpack-dev-server is not backporting the fix, one possible resolution is to update react to depend on newer version.