Skip to content

[packages/core] upgrade nanoid to 3.3.8 (CVE-2024-55565) #1763

Description

@madebyfabian

I got a dependabot security alert, that the @trigger.dev/sdk (via the /core package) npm package uses a nanoid version prior to 3.3.8, which has a vulnerability (see GHSA-mwcw-c2x4-8c55)

In my understanding, the core package (due to usage of the sdk package) is running in production code of users, so this incident seems valid.

If you feel this is not important, you can of course close this. Just wanted to bring this to attention :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions