"High" Severity Audit from dependency `css-select` and `css-what`
envgap__svg__svgo-1488
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
59876d894ba758814a224cffe26566104018130d- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
svg/svgo #1488 · read the original issue
**Describe the bug** Per [this advisory](https://www.npmjs.com/advisories/1754) installations that include `svgo` now cause an `npm audit` warning to appear because of the dependency on 3.x versions of `css-select`, which in turn depends on a version of `css-what` older than 5.0.1. **To Reproduce** 1. Add `svgo` as a dependency. 2. Run `npm audit` **Expected behavior** No audit should appear **Proposed fix** Upgrade the dependency on `css-select` to be `^4.1.3` since 4.1.3 bumps _their_ dependency on `css-what` to 5.0.1 and fixes this issue.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]