You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
uglifyjs-webpack-plugin is a legacy package. It has not been maintained for about 2 years, and is not likely to be updated.
Is it possible to migrate uglifyjs-webpack-plugin to other package to remediate this vulnerability?
I noticed several migration records for uglifyjs-webpack-plugin in other js repos, such as
in weaveworks-ui-components, version 0.22.5 ➔ 0.22.6, migrate from uglifyjs-webpack-plugin to terser-webpack-plugin via commit
in immortal-db, version 1.0.3 ➔ 1.1.0, migrate from uglifyjs-webpack-plugin to terser-webpack-plugin via commit
Are there any efforts planned that would remediate this vulnerability or migrate uglifyjs-webpack-plugin?
Thanks
; )
The text was updated successfully, but these errors were encountered:
Hi, @afc163, Several high vulnerabilities CVE-2019-16772, CVE-2019-16769, CVE-2020-7660 are introduced in @ant-design/tools via:
● @ant-design/[email protected] ➔ [email protected] ➔ [email protected]
uglifyjs-webpack-plugin is a legacy package. It has not been maintained for about 2 years, and is not likely to be updated.
Is it possible to migrate uglifyjs-webpack-plugin to other package to remediate this vulnerability?
I noticed several migration records for uglifyjs-webpack-plugin in other js repos, such as
Are there any efforts planned that would remediate this vulnerability or migrate uglifyjs-webpack-plugin?
Thanks
; )
The text was updated successfully, but these errors were encountered: