← All tasks
javascriptsvg/svgo #1488Not a task: already works

"High" Severity Audit from dependency `css-select` and `css-what`

envgap__svg__svgo-1488

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
59876d894ba758814a224cffe26566104018130d
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

svg/svgo #1488 · read the original issue
**Describe the bug**

Per [this advisory](https://www.npmjs.com/advisories/1754) installations that include `svgo` now cause an `npm audit` warning to appear because of the dependency on 3.x versions of `css-select`, which in turn depends on a version of `css-what` older than 5.0.1.



**To Reproduce**

1. Add `svgo` as a dependency.

2. Run `npm audit`



**Expected behavior**

No audit should appear

 

**Proposed fix**

Upgrade the dependency on `css-select` to be `^4.1.3` since 4.1.3 bumps _their_ dependency on `css-what` to 5.0.1 and fixes this issue.

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]