johnpapa / johnpapa/lite-server

Lite-server dependecies are vulnerable (The Async package have a vulnerability)

Open
#207 0 comments 5 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
2.3k
Forks
262
PR merge metrics
No merged PRs in 30d

Description

Lite-server dependecies are vulnerable (The Async package have a vulnerability)

When I install lite-server with de command npm install Lite-server appear that there are 4 high vulnerabilities.

First of all, I'm new with this technology so I can be wrong or something like that. By the way, the 4 High vulnerabilities come from a
vulnerable version of the Async package (This vulnerability was fixed in the cersion 2.6.4 and lite-server install the version 1.5.x). I actually don't know how to update Async (since is a nested dependency) but I think that is possible to change the predetermined version for installing and save money for the people who install lite-server (well, I don't know if it's possible but I think that it is).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.