Security vulnerability via transitive dependency on `serialize-javascript` via `rollup-plugin-terser`
Author: jagthedrummerCreated Apr 30, 2026Updated May 10, 2026
I've started to see vulnerability reports on a number of projects that all look like this: https://github.com/bullet-train-co/bullet_train-core/security/dependabot/557
The issue arises because microbundle depends on the deprecated rollup-plugin-terser package which has its dependency on serialize-javascript declared with ^4.0.0.
Updating microbundle to @rollup/plugin-terser should fix the dependency chain, but I don't know if it would introduce other issues.
Source: developit/microbundle