lpad-align breaks npm audit
Open
- Dominant language
- JavaScript
- Stars
- 8
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
On my last npm upgrade I ended up with 2 vulnerabilities, that won't fix, no matter what.
As it turns out lpad-align insists on pulling in meow@3.7.0
please update, thx
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating where lpad-align declares its meow dependency and run npm audit to confirm the reported vulnerabilities. Check whether the dependency can be updated without changing package behavior, then verify the audit is clean and the existing tests pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100