Vulnerability in static-evil dependency
Open
- Dominant language
- JavaScript
- Stars
- 9
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
npm audit reports that static-eval dependency has a vulnerability with regards to the version pulled in by sleuth. Needs to be upgraded to static-eval 2.0.0
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating sleuth's dependency declaration for static-eval and review the project's available tests or npm audit output. Done means the dependency resolves to static-eval 2.0.0 and the reported vulnerability is no longer present.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 42/100