Skip to content

Commit 3852d1f

Browse files
chore: remove serialize-javascript security exception
2 parents 925df80 + 25415b9 commit 3852d1f

1 file changed

Lines changed: 0 additions & 6 deletions

File tree

.iyarc

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -44,12 +44,6 @@ GHSA-7r86-cg39-jmmj
4444
# - Mitigated by controlled inputs (our own build scripts, not user-provided patterns)
4545
GHSA-23c5-xmqv-rm74
4646

47-
# Excluded because:
48-
# - Transitive devDependency through mocha, terser-webpack-plugin, copy-webpack-plugin
49-
# - serialize-javascript RCE via malicious RegExp.flags and Date.prototype.toISOString()
50-
# - Only affects dev-time tooling, not production code
51-
GHSA-5c6j-r48x-rmvq
52-
5347
# Excluded because:
5448
# - Transitive dependency through lerna and yeoman-generator requiring tar < 7.5.7
5549
# - This CVE affects tar's extraction process (hardlink path traversal in crafted archives)

0 commit comments

Comments
 (0)