Skip to content

Security vulnerability reported in highlight.js #28781

@wkilday

Description

@wkilday

Github's Dependabot is flagging Gatsby with a vulnerability in highlight.js@^8.1.0 via a dependency on [email protected].

The vulnerability is fixed in [email protected], which [email protected] uses.

Updating the hicat dependency in gatsby-recipes should resolve this vulnerability. Pull Request #28545 is already doing that, so getting it reviewed and merged should be enough.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type: bugAn issue or pull request relating to a bug in Gatsby

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions