Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency vulnerabilities #1005

Open
gkallenberg opened this issue May 22, 2019 · 1 comment
Open

Dependency vulnerabilities #1005

gkallenberg opened this issue May 22, 2019 · 1 comment

Comments

@gkallenberg
Copy link
Member

Reported by GitHub security:

  • hoek should be upgraded to at least v4.2.1 to mitigate a moderately severe vulnerability
  • url-parse should be upgraded to at least v1.4.3 to mitigate a highly severe vulnerability
  • cryptiles should be upgraded to at least v4.1.2 to mitigate a highly severe vulnerability
  • webpack-dev-server should be upgraded to at least v3.1.11 to mitigate a low severity vulnerability
  • just-extend should be upgraded to at least v4.0.0 to mitigate a low severity vulnerability
  • lodash should be upgraded to at least v4.17.11 to mitigate a low severity vulnerability
@siberry
Copy link
Contributor

siberry commented Feb 27, 2020

@gkallenberg, we do need to do a manual auditing of our package some point. Is this something that was autogenerated (like from dependabot or running npm audit)? Or did you curate this list to some degree?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants