db-migrate / db-migrate/node-db-migrate

semver related CVE and release

Open
#821 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
2.3k
Forks
361
PR merge metrics
No merged PRs in 30d

Description

## I'm submitting a...
- [ ] Bug report
- [ ] Feature request
- [x] Question

## Current behavior
I am using db-migrate in many projects, there is a fixed vulnerability in the `semver` dependency.
Currently our security checks are failing.
https://cwe.mitre.org/data/definitions/1333.html

## Expected behavior
`semver` should be updated to >= 7.5.2

## Minimal reproduction of the problem with instructions

`npm audit`

## What is the motivation / use case for changing the behavior?
We <3 security.

## Environment



db-migrate version: 0.11.13

Additional information:
- Node version: v20.3.1
- Platform: Linux

Others:
Thanks for your work.
It would be great to have a release or pre-release of current state :)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.