-
-
Notifications
You must be signed in to change notification settings - Fork 36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Several security vulnerabilities in dependency list #65
Comments
It also uses minimist@1.2.5 which has a critical security issue |
It also uses shell-quote, could you please update it to the latest as soon as possible? can anyone please look into this? |
I wish I could do something but I have no rights on that repository and my one and only PR never got merged 🤷 |
Hi @quilicicf, thanks for the quick reply. Is there any way to inform the owner other than GitHub? |
FYI: For time being we switched to https://www.npmjs.com/package/cpx-fixed mentioned in https://stackoverflow.com/questions/54996035/npm-copy-files-with-cpx-in-postinstall-script/59845967#59845967 - but of course it would be better when the "root" issue is addressed in this repository. |
I do not know the author unfortunately, so I have no clue what the best channel is to reach them :-( |
Sucks that it cant be taken over and community maintained, thus the JS ecosystem churns forward :( |
cpx defines a lot of vulnerabile dependencies, such as:
Can you please update these deps? @mysticatea
The text was updated successfully, but these errors were encountered: