We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 925df80 + 25415b9 commit 3852d1fCopy full SHA for 3852d1f
1 file changed
.iyarc
@@ -44,12 +44,6 @@ GHSA-7r86-cg39-jmmj
44
# - Mitigated by controlled inputs (our own build scripts, not user-provided patterns)
45
GHSA-23c5-xmqv-rm74
46
47
-# Excluded because:
48
-# - Transitive devDependency through mocha, terser-webpack-plugin, copy-webpack-plugin
49
-# - serialize-javascript RCE via malicious RegExp.flags and Date.prototype.toISOString()
50
-# - Only affects dev-time tooling, not production code
51
-GHSA-5c6j-r48x-rmvq
52
-
53
# Excluded because:
54
# - Transitive dependency through lerna and yeoman-generator requiring tar < 7.5.7
55
# - This CVE affects tar's extraction process (hardlink path traversal in crafted archives)
0 commit comments