framework icon indicating copy to clipboard operation
framework copied to clipboard

Security warning: esbuild

Open zachbogart opened this issue 7 months ago • 0 comments

I'm getting a security warning from Dependabot via esbuild. Looks like Framework uses esbuild and there is a dependency in Framework that may be patched with a recent update.

The latest possible version that can be installed is 0.20.2 because of the following conflicting dependencies:

@observablehq/[email protected] requires esbuild@^0.20.1 @observablehq/[email protected] requires esbuild@~0.23.0 via [email protected] No patched version available for esbuild The earliest fixed version is 0.25.0.

Transitive dependency esbuild 0.20.2 is introduced via @observablehq/framework 1.13.2 esbuild 0.20.2

Could this be updated internally?

Thanks!

zachbogart avatar Jul 13 '25 02:07 zachbogart