I got a dependabot security alert, that the @trigger.dev/sdk (via the /core package) npm package uses a nanoid version prior to 3.3.8, which has a vulnerability (see GHSA-mwcw-c2x4-8c55)
In my understanding, the core package (due to usage of the sdk package) is running in production code of users, so this incident seems valid.
If you feel this is not important, you can of course close this. Just wanted to bring this to attention :)
I got a dependabot security alert, that the
@trigger.dev/sdk(via the /core package) npm package uses a nanoid version prior to3.3.8, which has a vulnerability (see GHSA-mwcw-c2x4-8c55)In my understanding, the core package (due to usage of the sdk package) is running in production code of users, so this incident seems valid.
If you feel this is not important, you can of course close this. Just wanted to bring this to attention :)