There is a vulnerability in merge 1.2.1,upgrade recommended
Open
- Dominant language
- JavaScript
- Stars
- 193
- Forks
- 112
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L6871-L6873
CVE-2020-28499
Recommended upgrade version:2.1.1
Contributor guide
Research direction
Inspect acceptance/yarn.lock at lines 6871-6873, where the vulnerable merge 1.2.1 dependency is recorded. Update the dependency to the recommended 2.1.1 version and verify that the lockfile no longer references the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100