I've started to see vulnerability reports on a number of projects that all look like this: https://github.com/bullet-train-co/bullet_train-core/security/dependabot/557
The issue arises because microbundle depends on the deprecated rollup-plugin-terser package which has its dependency on serialize-javascript declared with ^4.0.0.
Updating microbundle to @rollup/plugin-terser should fix the dependency chain, but I don't know if it would introduce other issues.
I've started to see vulnerability reports on a number of projects that all look like this: https://github.com/bullet-train-co/bullet_train-core/security/dependabot/557
The issue arises because
microbundledepends on the deprecatedrollup-plugin-terserpackage which has its dependency onserialize-javascriptdeclared with^4.0.0.Updating
microbundleto@rollup/plugin-tersershould fix the dependency chain, but I don't know if it would introduce other issues.