Skip to content

fix: overrides audited vulnerabilities - #1217

Open
nicolaskempf57 wants to merge 2 commits into
mainfrom
fix/vulnerabilities
Open

fix: overrides audited vulnerabilities#1217
nicolaskempf57 wants to merge 2 commits into
mainfrom
fix/vulnerabilities

Conversation

@nicolaskempf57

@nicolaskempf57 nicolaskempf57 commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Note : audited from npm audit / dependabot not a real audit.

The xmldom update is the only one affecting a live env, coming from geopf-extensions-openlayers. But we are not in the vulnerable path of the CVE. The lib doesn't use requireWellFormed: true, and the lib parses a document. No call to Document#createEntityReference is ever made.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant