Skip to content

Security vulnerability: rollup-plugin-size uses vulnerable axios #349

@louayaz1

Description

@louayaz1

The devDependency rollup-plugin-size is currently at version 0.2.1, which relies on axios <0.30.0. This version of axios is affected by CVE-2025-27152 (high severity). Please update rollup-plugin-size to version 0.3.0 or higher to remove the vulnerable axios from the dependency tree. This change only affects development tooling and should not introduce breaking changes.

References:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions