-
Notifications
You must be signed in to change notification settings - Fork 128
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependencies #430
Update dependencies #430
Conversation
maxbeatty
commented
Oct 4, 2017
•
edited
Loading
edited
- in range version bumps
- joi Update joi to the latest version 🚀 #424
- code Update code to the latest version 🚀 #425
- hoek Update hoek to the latest version 🚀 #426
- boom Update boom to the latest version 🚀 #427
- catbox Update catbox to the latest version 🚀 #428
- sinon Update sinon to the latest version 🚀 #417 Migrate to Sinon 3 #419
- switch from marked (insecure and abandoned) to marky-markdown (powers npmjs.com)
relaxing the Node Security PR check since there's no upstream fix :( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
Linking the one issue node security flagged. It's not clear what module uses timespan (likely Joi?) but I know we're not using it directly to validate anything. |
Path to vulnerability: good-loggly@3.1.0 > loggly@1.1.1 > timespan@2.3.0. Might be awhile before all 3 get bumped w/ fix. |