Upgrade mkdirp due to vulnerability in old version
オープン
- 主要言語
- JavaScript
- スター
- 156
- フォーク
- 18
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Trying to work back through each node module for `bunyan` to fix a vulnerability.
`mkdirp@0.5.1` has a vulnerable package `minimist@0.0.8` which needs to be fixed. Updating to the latest version of `mkdirp` will completely remove `minimist` from the dependency tree.
Here's the CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-7598
This library hasn't had any movement on it for quite a long time. If it's dead, say it's dead so I can discuss this with the maintainers of `bunyan`
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。