Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in outdated dependency #11

Open
dmcpton opened this issue Nov 11, 2018 · 1 comment
Open

Security vulnerability in outdated dependency #11

dmcpton opened this issue Nov 11, 2018 · 1 comment

Comments

@dmcpton
Copy link

dmcpton commented Nov 11, 2018

The version of Cheerio which this package requires is an old version, which itself then requires an outdated version of lodash, which contains a security vulnerability. I'm not sure which of the latest versions of Cheerio would work, but could you update that dependency? Thanks!

@dmcpton
Copy link
Author

dmcpton commented Nov 11, 2018

Oops, I posted this in the wrong repo, this was meant for node-cas. Regardless, there is a security vulnerability, it's just one dependency deeper. If anyone knows someone who can address this issue, that would be awesome. If I have time, I'll fork the dependency and submit a pull request to change the dependency to my fork, if that would be an acceptable solution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant