Commit 7e87885
build(deps): Fix GHSA-5gfm-wpxj-wjgq in node-forge, bump @rspack packages
Bump @rspack/cli and @rspack/core from 1.7.3 to 1.7.6 and
@rspack/plugin-react-refresh from 1.6.0 to 1.6.1.
The vulnerable node-forge@1.3.1 is introduced transitively via
@rspack/cli → @rspack/dev-server@1.1.5 → webpack-dev-server@5.2.2
→ selfsigned@2.4.1 → node-forge@^1. Since no 1.x version of
@rspack/dev-server yet pins webpack-dev-server@5.2.3 (which dropped
node-forge entirely), add a pnpm override forcing node-forge>=1.3.2
to resolve the vulnerability independently of the dep chain.
Co-Authored-By: Claude <noreply@anthropic.com>1 parent 3da4a6d commit 7e87885
2 files changed
+124
-141
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
65 | | - | |
66 | | - | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
| |||
0 commit comments