bahmutov / bahmutov/stop-only

execa version security vulnerability

Open
#152 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
11
Forks
5
PR merge metrics
No merged PRs in 30d

Description

Thank you for the package!

The dependency on execa@0.11.0 is making this package a critical security vulnerability when running `npm audit`.

- version: 3.3.1

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating the package manifest and checking how execa@0.11.0 is declared. Run npm audit to confirm the vulnerability and identify a compatible non-vulnerable version, then verify that the audit is clean and the package still works.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
cli, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.