Skip to content

Conversation

@hughie-ada
Copy link

As outlined in the issue I created, there is a critical vulnerability in versions of pbkdf < 3.1.3. This PR simply bumps the version of pbkdf from 3.1.2 -> 3.1.3.

There are many newer versions, but I wanted to keep this change as low risk and minimal as possible.

@ljharb
Copy link
Member

ljharb commented Nov 8, 2025

It’s using a semver range; no change here is needed. #252 (comment)

@ljharb ljharb closed this Nov 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants