inflight@1.0.6 memory leak detected by Snyk — will Docusaurus remove this dependency?
B
Bartłomiej Ciernia
Hello!
Running a Snyk audit on @docusaurus/core@3.8.1 shows a Medium severity issue with inflight@1.0.6 (abandoned package, known memory leak): @docusaurus/core → @docusaurus/utils → shelljs@0.8.5 → glob@7.x → inflight@1.0.6
inflight has no patch and is unmaintained.
glob@9 and rimraf@4+ removed this dependency.
Is there a plan to drop shelljs / upgrade dependencies so that inflight is no longer pulled in?