# improved-yarn-audit advisory exclusions GHSA-257v-vj4p-3w2h # yarn berry's `yarn npm audit` script reports the following vulnerability but # it is a false positive. The offending version of 'ws' that is installed is # 7.1.1 and is included only via remote-redux-devtools which is a devDependency GHSA-6fc8-4gx4-v693 # request library is subject to SSRF. # addressed by temporary patch in .yarn/patches/request-npm-2.88.2-f4a57c72c4.patch GHSA-p8p7-x288-28g6