#23 CVE-2021-23368 in vue dependencies
Closed by mymindstorm. Opened by abitrolly.

I've got security scanner complaints that https://pagure.io/fedora-packages-static/blob/master/f/vue contains this CVE https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595


I don't think that this is actually exploitable. Will run npm audit fix when I am able to work on packages static more.

Too bad that nobody can say for sure. Warnings are annoying.

The JS world is kind of a pain for this - I'd say that there's not much to do on our side, except bumping the view dependency when an update is available:

  • AFAIK you can't feed arbitrary data here.
  • Worst case the client's browser tab gets unresponsive.
  • It'll eventually be fixed upstream.

Metadata Update from @mymindstorm:
- Issue status updated to: Closed (was: Open)

Fixed by https://pagure.io/fedora-packages-static/c/a664997a5ba606d2fa1bb80397e672d58173bf4e?branch=master

Metadata