Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NPM audit reports low vulnerability in dependencies #592

Open
LoganDupont opened this issue May 18, 2020 · 4 comments
Open

NPM audit reports low vulnerability in dependencies #592

LoganDupont opened this issue May 18, 2020 · 4 comments
Labels

Comments

@LoganDupont
Copy link

Paths:

  • standard-version > git-semver-tags > meow > yargs-parser

  • standard-version > conventional-recommended-bump > meow > yargs-parser

  • standard-version > conventional-recommended-bump > git-semver-tags > meow > yargs-parser

More info https://npmjs.com/advisories/1500

@saadjutt01
Copy link

saadjutt01 commented May 19, 2020

Low : Prototype Pollution
Package : yargs-parser
Patched in : >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2
Dependency of : standard-version [dev]
on console.

@timbru31
Copy link

timbru31 commented Jun 8, 2020

Both conventional-recommended-bump@6.0.9 and git-semver-tags@4.0.0 already have been released - we just need a review and merge of their dependency PRs: #588 #598

Can someone please take care of this and release a new version? The PRs are open since >1 month now...

@jbottigliero
Copy link
Member

Hi, we've published 8.0.1 which includes updates for both of these dependencies.

@nmccready
Copy link

Any updates please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Development

No branches or pull requests

5 participants