suddjian edited a comment on issue #17002:
URL: https://github.com/apache/superset/issues/17002#issuecomment-940583667


   Thanks for bringing these forward. In the future, please send an email to 
[email protected] rather than opening a public issue.
   
   I am investigating these. I will reference this issue from my PRs and/or 
update this comment as I go through them.
   
   - esm (`GHSA-qx4v-6gc5-f2vv`) is referenced by a deeply nested dependency 
(mapbox-gl). In that library, esm is used for builds, which should not affect 
this project.
   - highlight.js (`GHSA-7wwv-vh3v-89cq`) is referenced by both dependencies 
(via react-syntax-highlighter) and devDependencies (via several storybook 
packages). I am only going to upgrade react-syntax-highlighter, as the 
storybook usage is only relevant during development.
   - immer (`CVE-2021-23436` and `CVE-2021-3757`) is up-to-date as referenced 
directly by Superset. Version `8.0.1` with the vulnerability is used only by 
Storybook and does not affect Superset itself.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to