
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
A GitHub-reviewed security advisory — not necessarily under active exploitation the way our CISA KEV advisories are, but a real, disclosed vulnerability in an open-source dependency.
Affected packages
Vulnerable: >= 2.2.0, <= 2.8.4
Patched in 2.8.5
Vulnerable: >= 2.9.0, <= 2.9.3
Patched in 2.9.4
Vulnerable: >= 2.10.0, <= 2.10.4
Patched in 2.10.5
Vulnerable: >= 3.0.0-alpha.1, <= 3.0.0-alpha.4
Patched in 3.0.0-beta.1
Vulnerable: >= 3.0.0-alpha.8, <= 3.0.0-alpha.10
Patched in 3.0.0-beta.1
Vulnerable: >= 1.0.0-rc.1, <= 1.6.1.1
Patched in 2.0.2
Details
Talk to us about this
Find out whether this dependency (or others like it) is actually reachable in your codebase.
Get help patching, or building dependency-scanning into your pipeline going forward.
A secure code review or supply chain review finds this before an advisory does.