Skip to content

Conversation

@yashwason
Copy link

The version of the dependancy 'xmldom' being used in this package has been found to have certain vulnerabilities that may lead to unexpected syntactic changes during XML processing in some downstream applications.

More here -> https://www.npmjs.com/advisories/1650

@rathishcholarajan
Copy link

Thanks @yashwason !
@jaredhanson could you please help merge this change?

@allanice001
Copy link

@rathishcholarajan @jaredhanson ping

@steliosrammos
Copy link

Is there an ETA on merging this PR?

@Martii
Copy link

Martii commented Mar 14, 2022

Just a FYI... as of right now https://www.npmjs.com/package/@xmldom/xmldom is the new location for ~xmldom so this PR is probably invalidated. (also mentioned in #2)

@yashwason yashwason closed this Jan 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants