New patch required to mitigate high risk vulnerability
Author: andreasonny83Created May 18, 2022Updated May 18, 2022
@istarkov, the fbjs dependency was removed time ago and the PR is already merged into master. However, the latest 0.30.0 version of recompose is still injecting that package inside as it doesn't contain the latest changes to the package.json.
The fbjs is currently pulling inside a vulnerable version of node-fetch making any package consuming recompose as High risk.
Can you please trigger a new release to finally get rid of that extra dependency?
Thank you
Source: acdlite/recompose