Skip to content

Security vulnerability via transitive dependency on serialize-javascript via rollup-plugin-terser #1100

Description

@jagthedrummer

I've started to see vulnerability reports on a number of projects that all look like this: https://github.com/bullet-train-co/bullet_train-core/security/dependabot/557

The issue arises because microbundle depends on the deprecated rollup-plugin-terser package which has its dependency on serialize-javascript declared with ^4.0.0.

Updating microbundle to @rollup/plugin-terser should fix the dependency chain, but I don't know if it would introduce other issues.

Activity

  1. rschristian commented on Apr 30, 2026

    @rschristian
    Collaborator

    Your link 404's, but like most "vulnerabilities" in build tooling, it's likely they're completely non-applicable for users. They tend to only be relevant if you're running untrusted user data through it on (say) a web server.

    That being said, Microbundle is no longer maintained so it's unlikely those audit warnings will go away.

  2. jagthedrummer commented on Apr 30, 2026

    @jagthedrummer
    Author

    Oops, sorry, didn't realize that link was protected. But thanks for the info about microbundle being unmaintained. We'll look for an alternative.

  3. daun commented on May 8, 2026

    @daun
    Contributor

    @rschristian Would be great to have a short notice on the repo saying microbundle is unmaintained.

  4. rschristian commented on May 10, 2026

    @rschristian
    Collaborator

    Unfortunately I don't have maintainer rights here and wrangling the couple people that do is pretty tricky these days; it's unlikely that anything, even a ReadMe change, will get merged in.

    Also, not my repo & Preact itself still uses it, so slapping a "Unmaintained" label isn't really my call :/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions