-
-
Notifications
You must be signed in to change notification settings - Fork 62
Open
Description
This package depends on eonasdan-bootstrap-datetimepicker
version 4.17.49 which depends on bootstrap
version 3.4.1 and moment-timezone
version 0.4.1. These transitive dependencies have vulnerabilities, which is causing vulnerability scan results for my project which uses django-bootstrap-datepicker-plus
.
The vulnerabilities are:
- GHSA-9mvj-f7w8-pvh2 (
bootstrap
) - GHSA-v78c-4p63-2j6c (
moment-timezone
)
It's possible that eonasdan-bootstrap-datetimepicker
does not use these dependencies in a vulnerable manner, but it would be nice to update the dependencies of django-bootstrap-datepicker-plus
to fix these vulnerability scan results.
Metadata
Metadata
Assignees
Labels
No labels