Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Critical Security] Bump @module-federation/enhanced to 0.9.0 #772

Open
2 tasks
alex50105 opened this issue Feb 21, 2025 · 0 comments
Open
2 tasks

[Critical Security] Bump @module-federation/enhanced to 0.9.0 #772

alex50105 opened this issue Feb 21, 2025 · 0 comments

Comments

@alex50105
Copy link

alex50105 commented Feb 21, 2025

For which library do you have a feature request?

module-federation

Information

Koa has a critical security vulnerability: GHSA-593f-38f6-jp5m
and it is a indirect dependency of module-federation:

@angular-architects/[email protected]
  └─┬ @angular-architects/[email protected]
    └─┬ @module-federation/[email protected]
      └─┬ @module-federation/[email protected]
        └── [email protected]

The vulnerability is fixed in [email protected] and there is a new version of @module-federation/enhanced (0.9.0) that bumps koa to the save 2.15.4

Describe any alternatives/workarounds you're currently using

No response

I would be willing to submit a PR to fix this issue

  • Yes
  • No
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants