Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update mermaid-js to 9.4.0, because all versions between 9.1.1 and 9.3.0 use moment-js 2.24.0 as a transitive dependency. moment-js 2.24.0 has two vulnerabilities with CVE identifiers: CVE-2022-31129, CVE-2022-24785. Both of them are with HIGH severity. Luckily, they have been fixed in moment-js 2.29.4 and mermaid-js 9.4.0 depends on this fixed version.
Therefore, I would like to propose a version update for mermaid-js.
Without this update,
quarkus-vertx-http-deployment
can get marked as a vulnerable library by a dependency checking tool. That is because mermaid-js is packed insidequarkus-vertx-http-deployment
.