Skip to content

Dependency update to resolve npm audit issues #16

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Taenick opened this issue Jun 11, 2021 · 1 comment · Fixed by #18
Closed

Dependency update to resolve npm audit issues #16

Taenick opened this issue Jun 11, 2021 · 1 comment · Fixed by #18
Labels
Type: Security Vulnerability disclosure or Fixing security issue

Comments

@Taenick
Copy link

Taenick commented Jun 11, 2021

Hello,

This project is causing npm audit to fail for my builds, I was hoping it is ok if I submit a pr to resolve the audit issues.

` === npm audit security report ===

┌──────────────────────────────────────────────────────────────────────────────┐
│ Manual Review │
│ Some vulnerabilities require your attention to resolve │
│ │
│ Visit https://go.npm.me/audit-guide for additional guidance │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ trim-newlines │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=3.0.1 <4.0.0 || >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ can-npm-publish [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ can-npm-publish > meow > trim-newlines │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1753
└───────────────┴──────────────────────────────────────────────────────────────┘
`

@azu
Copy link
Owner

azu commented Jun 11, 2021

@azu azu closed this as completed Jun 11, 2021
@azu azu added the Type: Security Vulnerability disclosure or Fixing security issue label Jun 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Type: Security Vulnerability disclosure or Fixing security issue
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants