Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in Minimist #273

Closed
shawnemhe opened this issue Sep 8, 2020 · 5 comments
Closed

Vulnerability in Minimist #273

shawnemhe opened this issue Sep 8, 2020 · 5 comments

Comments

@shawnemhe
Copy link

Npm audit is finding a vulnerability in the minimist package. This is coming through as a dependency of optimist. That package currently has a deprecation notice and is not likely to be updated. The package owner recommends using minimist directly, or nomnom.

Are there any efforts planned that would remediate this vulnerability?

@DevRCRun
Copy link

DevRCRun commented Sep 18, 2020

Snyk is flagging this for us too. There are some pull requests open to resolve, might be an idea to vote on the one you agree with

#267
#263

@shawnemhe
Copy link
Author

@DevRCRun, I'll take a look at the PRs.

@coreybutler
Copy link
Owner

#267 is the one I will merge once it has been tested.

@seidhkona
Copy link

Any plans on merging this anytime soon? Thanks!

@coreybutler
Copy link
Owner

Resolved with PR #267.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants