There is a vulnerability in mixin-deep 1.3.1,upgrade recommended
Open
- Dominant language
- JavaScript
- Stars
- 193
- Forks
- 112
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L7047-L7049
CVE-2019-10746
Recommended upgrade version:1.3.2
Contributor guide
Research direction
Open acceptance/yarn.lock at lines 7047–7049 and inspect the mixin-deep dependency entry. Update the locked version from 1.3.1 to the recommended 1.3.2, then verify that the lockfile no longer resolves the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100