andrewrk / andrewrk/node-mv

Upgrade mkdirp due to vulnerability in old version

オープン
#33 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
JavaScript
スター
156
フォーク
18
PR マージ指標
30日以内にマージされた PR はありません

説明

Trying to work back through each node module for `bunyan` to fix a vulnerability.

`mkdirp@0.5.1` has a vulnerable package `minimist@0.0.8` which needs to be fixed. Updating to the latest version of `mkdirp` will completely remove `minimist` from the dependency tree.

Here's the CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-7598

This library hasn't had any movement on it for quite a long time. If it's dead, say it's dead so I can discuss this with the maintainers of `bunyan`

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。