Skip to content

Remove unused dependency happy-dom that has a critical security vulnerability#96

Open
thms-rmb wants to merge 1 commit intoIIIF-Commons:masterfrom
tind:remove-unused-dependency-happy-dom
Open

Remove unused dependency happy-dom that has a critical security vulnerability#96
thms-rmb wants to merge 1 commit intoIIIF-Commons:masterfrom
tind:remove-unused-dependency-happy-dom

Conversation

@thms-rmb
Copy link
Copy Markdown

@thms-rmb thms-rmb commented Mar 6, 2025

There is a critical security vulnerability in the package happy-dom (https://security.snyk.io/vuln/SNYK-JS-HAPPYDOM-8350065), which appears to be unused here. Nevertheless, it gets flagged by tools such as dependabot. It appears that the easiest solution here is to just remove the dependency.

@codesandbox-ci
Copy link
Copy Markdown

codesandbox-ci bot commented Mar 6, 2025

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant