Autodesk / Autodesk/hig

There is a vulnerability in mixin-deep 1.3.1,upgrade recommended

Open
#2,497 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
193
Forks
112
PR merge metrics
No merged PRs in 30d

Description

https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L7047-L7049

CVE-2019-10746

Recommended upgrade version:1.3.2

Contributor guide

Open the contributing guide

Research direction

Open acceptance/yarn.lock at lines 7047–7049 and inspect the mixin-deep dependency entry. Update the locked version from 1.3.1 to the recommended 1.3.2, then verify that the lockfile no longer resolves the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.