Skip to content

Several high vulnerabilities CVE-2019-16772, CVE-2019-16769, CVE-2020-7660 are introduced in create-elm-appΒ #599

@ayaka-kms

Description

@ayaka-kms

Hi, several high vulnerabilities CVE-2019-16772, CVE-2019-16769, CVE-2020-7660 are introduced in create-elm-app via:
● [email protected] βž” [email protected] βž” [email protected]

uglifyjs-webpack-plugin is a legacy package. It has not been maintained for about 2 years, and is not likely to be updated.
Is it possible to migrate uglifyjs-webpack-plugin to other package to remediate this vulnerability?

I noticed several migration records for uglifyjs-webpack-plugin in other js repos, such as

  1. in weaveworks-ui-components, version 0.22.5 βž” 0.22.6, migrate from uglifyjs-webpack-plugin to terser-webpack-plugin via commit
  2. in immortal-db, version 1.0.3 βž” 1.1.0, migrate from uglifyjs-webpack-plugin to terser-webpack-plugin via commit

Are there any efforts planned that would remediate this vulnerability or migrate uglifyjs-webpack-plugin?

Thanks
; )

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions