Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Security Vulnarability is detected in the library CVE-2021-23346 #28

Closed
pavanjava opened this issue Apr 2, 2021 · 3 comments
Closed

Comments

@pavanjava
Copy link

Hi Team, the html-parse-stringify2 is a transitive dependency and the latest version available is 2.0.1 and there is a CVE-2021-23346 detected in the latest version. is this library activly maintained ?? if yes is any one actively looking into it.

@SeinopSys
Copy link

Considering the latest publish was nearly half a decade ago I would suggest you look into the original package which this is a fork of, html-parse-stringify. If you are depending on this transitively through react-i18next there's already some progress on replacing this package with it here: i18next/react-i18next#1283

@pavanjava
Copy link
Author

@SeinopSys : thanks for the clarification will check at the react-i18next and the html-parse-stringify directly.

@modestfake
Copy link

modestfake commented Apr 12, 2021

@rayd have all of the fixes that were introduced in this fork been merged into the original repository? If so, could you please add a note to the README.md to advise using the original repo instead?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants