Skip to content

Conversation

jakehobbs
Copy link

https://nvd.nist.gov/vuln/detail/CVE-2025-6545

  • update version pbkdf2 3.1.2 => 3.1.3

@ljharb
Copy link
Member

ljharb commented Aug 30, 2025

There's no need for this, and there's never a need for any PR like it. The fix is an in-range version, so all everyone needs to do is update their lockfiles (which npm audit fix, dependabot/renovate/etc, all do for you).

@ljharb ljharb closed this Aug 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants