Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tech run/9212 vtk vunlnerability #9214

Closed

Conversation

tech-run
Copy link

↪️ Pull Request

A vulnerability was found in lz4. lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to GHSA-gmc7-pqv9-966m. lz4. lz4-sys are held withing lmdb package which has a new 2.8.5 release which fixes the vulnerability as this a dependnecy of @paracel/cache looking to update the parcel package.

This PR resolves issue 9212 vtk vunlnerability

💻 Examples

N/A Dependency update

🚨 Test instructions

ran existing yarn tests and attached results

✔️ PR Todo

yarn_test.log

  • Added/updated unit tests for this change
  • Filled out test instructions (In case there aren't any unit tests)
  • [x ] Included links to related issues/PRs

@mischnic mischnic closed this Sep 19, 2023
@mischnic mischnic mentioned this pull request Sep 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants