Project

General

Profile

Actions

Bug #23228

open

Upgrade (or remove) react-dnd

Added by Stephen Smith 5 months ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Assigned To:
-
Category:
Workbench2
Target version:
Story points:
-
Release relationship:
Auto

Description

react-dnd has a transitive dependency on a vulnerable node-fetch through recompose

We should either upgrade it to ^7.4.0 or above
or remove it, since it's only used in Chips, and dragging and dropping them doesn't seem to work anyway?

Actions #1

Updated by Stephen Smith 5 months ago

  • Description updated (diff)
Actions

Also available in: Atom PDF