Skip to content

Conversation

@mmarinova-mm
Copy link

@mmarinova-mm mmarinova-mm commented Aug 21, 2025

We are getting xml2js flagged in one of our vulnerability scans for https://nvd.nist.gov/vuln/detail/CVE-2023-0842

This seeks to upgrade xml2js to a fixed version.

cognito-local is already in my dev dependencies but unfortunately the scanner is overzealous and detects it and its dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant