Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot cannot update esbuild to a non-vulnerable version #4580

Closed
rdeavila opened this issue Feb 25, 2025 · 1 comment
Closed

Dependabot cannot update esbuild to a non-vulnerable version #4580

rdeavila opened this issue Feb 25, 2025 · 1 comment

Comments

@rdeavila
Copy link

Hello!

I didn't use any issue template since this is not a but nor a feature request 😃

I have this Dependabot alert on my repo, but he can't do any change since esbuild can't be updated to the mentioned version. I saw a PR #4558 which do this upgrade, but it was closed.

There's something I can do? Or just ignore this alert?

https://github.com/rdeavila/rda.run/security/dependabot/17

Dependabot cannot update esbuild to a non-vulnerable version
The latest possible version that can be installed is 0.21.5 because of the following conflicting dependencies:

[email protected] requires esbuild@^0.21.3 via [email protected]
No patched version available for esbuild
The earliest fixed version is 0.25.0.
@brc-dd
Copy link
Member

brc-dd commented Feb 25, 2025

You can discard that vulnerability report. VitePress and Vite don't use the impacted functionality of esbuild. vitejs/vite#19412, vitejs/vite#19428

@brc-dd brc-dd closed this as not planned Won't fix, can't repro, duplicate, stale Feb 25, 2025
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 5, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants