Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update minimist version to fix security issues #708

Open
Twinbird24 opened this issue Mar 24, 2022 · 2 comments
Open

Update minimist version to fix security issues #708

Twinbird24 opened this issue Mar 24, 2022 · 2 comments

Comments

@Twinbird24
Copy link

One of the dependencies used in this project, minimist, should be updated from 1.2.5 to 1.2.6 to include this security fix.

@kreintjes
Copy link

kreintjes commented Apr 7, 2022

I get a dependabot warning that this is a critical security vulnerability, but now can't update due to this package hard-locking minimist's version. There also already is a PR to update this dependency: #710. Maybe somebody can have a look at this with some priority?

Also it might be worth considering to use a progressive lock (e.g. ^1.2.6) instead of a hard lock for minimist (and other dependencies) instead.

yanovich pushed a commit to yanovich/prettierx that referenced this issue May 20, 2022
@LeviPesin
Copy link

Related: brodycj/prettier-x-formatter#1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants