Need update dependence called @graphql-tools/prisma-loader to 8.0.2 for addressing vulnerabilities in jose v4.14.4 #9904
Closed
keisuke-na
started this conversation in
Announcements
Replies: 1 comment
-
It was simply a matter of updating the prisma-loader. My apologies. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The @graphql-codegen/cli v5.0.2 use @graphql-tools/prisma-loader to 8.0.1 which use jose v4.14.4.
There is vulnerabilities on jose v4.14.4 which is used by @graphql-tools/prisma-loader to 8.0.1.
Please see this alert => GHSA-hhhv-q57g-882q
Beta Was this translation helpful? Give feedback.
All reactions