Hey there.
We are tracking CVEs for our projects and data grid premium is causing warnings because of GHSA-w5hq-g745-h8pq.
The @mui/x-data-grid-premium@8 package depends on @mui/x-internal-exceljs-fork@4 which depends on uuid@8.
Now the CVE specifically states that uuid v4 is not affected and from this exceljs issue text i would assume that your internal fork also only uses uuid v4.
So this CVE is probably not that relevant to you. Would just like to get rid of the CVE in our tracker.
Would it be possible for you to upgrade your uuid dependency to package version 14?
Thanks
Hey there.
We are tracking CVEs for our projects and data grid premium is causing warnings because of GHSA-w5hq-g745-h8pq.
The @mui/x-data-grid-premium@8 package depends on @mui/x-internal-exceljs-fork@4 which depends on uuid@8.
Now the CVE specifically states that uuid v4 is not affected and from this exceljs issue text i would assume that your internal fork also only uses uuid v4.
So this CVE is probably not that relevant to you. Would just like to get rid of the CVE in our tracker.
Would it be possible for you to upgrade your uuid dependency to package version 14?
Thanks