You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I noticed that the GitHub advisory for GHSA-x8rq-rc7x-5fg5 lists the vulnerable package as uppy, whereas the actual vulnerable package appears to be @uppy/component.
I have also verified the advisory for any potential transitive dependencies. Based on the vulnerable version range specified (< 2.3.3) on the npm page (https://www.npmjs.com/package/uppy/v/2.3.2), there is no indication that the uppy package includes a dependency on @uppy/component.
Could you please review this and make any necessary corrections to the advisory?