minimist security vulnerability
Open
- Dominant language
- JavaScript
- Stars
- 7.2k
- Forks
- 621
- PR merge metrics
- No merged PRs in 30d
Description
Is there an alternative to `portfinder` that could be used?
They don't seem super interested in upgrading `mkdirp` which relies on a vulnerable version of `minimist`
https://github.com/http-party/node-portfinder/issues/112
Unfortunately my company has a mono-repo and this bar is pretty much constantly there due to NPM dependencies, and I keep getting a hard time about it 😬
`minimist` CVE:
https://github.com/advisories/GHSA-xvch-5gv4-984h

Contributor guide
Assessment
This issue has not been assessed yet.