Skip to content
This repository has been archived by the owner on Jan 21, 2024. It is now read-only.

fix(dependencies): bumping version of yargs to deal with nexus vulner… #186

Merged
merged 1 commit into from Jun 19, 2019

Conversation

wsolem
Copy link
Contributor

@wsolem wsolem commented Jun 18, 2019

…abilities

yargs/yargs#1356
yargs < 13.3.0 include os-local, which has execa as a dependency
all versions of execa are vulnerable to command injection attacks.

@jstoiko
Copy link
Contributor

jstoiko commented Jun 19, 2019

Thanks for this @wsolem. I can npm publish whenever you want me to. Are any Osprey dependencies affected?

@wsolem
Copy link
Contributor Author

wsolem commented Jun 19, 2019

awesome. I messaged you directly responding to your question. Thank you!

@jstoiko jstoiko merged commit 1e3eb01 into master Jun 19, 2019
@jstoiko jstoiko deleted the fix/CS-5281 branch June 19, 2019 21:48
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants