You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'd like to request a correction to the advisory GHSA-gjph-xf5q-6mfq for the @hapi/ammo package.
Currently, the advisory lists only @hapi/ammo as the affected package with the following vulnerable version ranges: < 3.1.2, >= 4.0.0, < 5.0.1
However, the legacy ammo package (prior to the scoped @hapi/ammo) also includes vulnerable versions and should be included in the advisory as well. The package ammo on npm includes versions published before the scoped rename to @hapi/ammo.