Hello,
I’m using @ant-design/[email protected] (latest at the time of writing), and noticed it’s still pulling [email protected], which is affected by a critical RCE vulnerability (CVE-2021-23358).
Here’s the relevant dependency path:
Would you be open to updating or replacing these dependencies to eliminate the risk from the outdated underscore?
Thanks!