andrewrk / andrewrk/node-mv

Upgrade mkdirp due to vulnerability in old version

未关闭
#33 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
156
派生
18
PR 合并指标
30 天内没有已合并 PR

描述

Trying to work back through each node module for `bunyan` to fix a vulnerability.

`mkdirp@0.5.1` has a vulnerable package `minimist@0.0.8` which needs to be fixed. Updating to the latest version of `mkdirp` will completely remove `minimist` from the dependency tree.

Here's the CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-7598

This library hasn't had any movement on it for quite a long time. If it's dead, say it's dead so I can discuss this with the maintainers of `bunyan`

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。