Skip to content

[GHSA-w4pp-8pjf-rmxw] Versions of the package pacote from 11.2.7 are vulnerable...#8036

Open
Capco-srachels wants to merge 1 commit into
Capco-srachels/advisory-improvement-8036from
Capco-srachels-GHSA-w4pp-8pjf-rmxw
Open

[GHSA-w4pp-8pjf-rmxw] Versions of the package pacote from 11.2.7 are vulnerable...#8036
Capco-srachels wants to merge 1 commit into
Capco-srachels/advisory-improvement-8036from
Capco-srachels-GHSA-w4pp-8pjf-rmxw

Conversation

@Capco-srachels

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • Severity
  • Summary

Comments
Requesting update to this advisory to include a fixed version of 21.5.1 and affected version range of >= 11.27 to < 21.5.1.
Here's the changelog from pacote 21.5.1 showing the fix: https://github.com/npm/pacote/blob/v21.5.1/CHANGELOG.md

Copilot stopped work on behalf of Capco-srachels due to an error June 13, 2026 00:11
@github-actions github-actions Bot changed the base branch from main to Capco-srachels/advisory-improvement-8036 June 13, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant