Laravel-mix: CVE-2021-28092

Created on 22 Mar 2021  路  5Comments  路  Source: JeffreyWay/laravel-mix

  • Laravel Mix Version: v6.0.13
  • Node Version (node -v): v14.16.0
  • NPM Version (npm -v): v6.14.11
  • OS: Ubuntu 20.04

[email protected] requires is-svg@^3.0.0 via a transitive dependency on [email protected]

https://github.com/advisories/GHSA-7r28-3m3f-r2pr

Most helpful comment

This is due to our dependency of cssnano. I believe the only resolution right now is to use yarn + yarn resolutions to fix this. They have not released (and appears will not release) a fix in a non-major version.

All 5 comments

Same issue in [email protected] which also seems to be affected by CVE-2021-27290.

This is due to our dependency of cssnano. I believe the only resolution right now is to use yarn + yarn resolutions to fix this. They have not released (and appears will not release) a fix in a non-major version.

It is also discuted here. It seems there is a 5.0.0-rc.2 version, but it needs to be specified/forced because latest stable release on NPM is currently 4.1.10

this issue fixed in [email protected] you should update your dependencies

Was this page helpful?
0 / 5 - 0 ratings

Related issues

RomainGoncalves picture RomainGoncalves  路  3Comments

jpmurray picture jpmurray  路  3Comments

rlewkowicz picture rlewkowicz  路  3Comments

jpriceonline picture jpriceonline  路  3Comments

stefensuhat picture stefensuhat  路  3Comments