Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
minimist@1.2.2 and earlier had "a prototype pollution bug that could cause privilege escalation in some circumstances when handling untrusted user input." [Source: https://github.com/substack/minimist#security] Unfortunately, mocha@7.x also has a dependency on a vulnerable minimist version through the mkdirp package; but at this point it seems likely that this will only get addressed in mocha@8.0: mochajs/mocha#4199. This update partially addresses the security alert raised by GitHub in https://github.com/aerospike/aerospike-client-nodejs/network/alert/package-lock.json/minimist/open
- Loading branch information