Skip to content
This repository has been archived by the owner on Dec 28, 2023. It is now read-only.

Usage of exact version of minimist #214

Open
z0r0132 opened this issue Apr 6, 2020 · 4 comments
Open

Usage of exact version of minimist #214

z0r0132 opened this issue Apr 6, 2020 · 4 comments

Comments

@z0r0132
Copy link

z0r0132 commented Apr 6, 2020

The version used for minimist is 1.2.0.
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.

I cannot change in my project, even if I install latest of minimist, karma-mocha still install 1.2.0 and uses it, can you please check that and update, it is critical in my project.
Thanks

@franktopel
Copy link
Contributor

franktopel commented Apr 6, 2020

To whoever is able to maintain this project:

Additional information

Please see https://npmjs.com/advisories/1179 as of what exactly is the problem here.

karma itself has this problem, and they have addressed it in this commit. The only thing currently preventing @johnjbarton from releasing a new version of karma containing that fix seems to be Travis-related problems which aforementioned repo owner announced to address today.

Please upgrade your dependency asap to a version >= 1.2.3.

@franktopel
Copy link
Contributor

@johnjbarton The latest release of this package dates back to 2016. Who can issue a new release with this fix in it?

@johnjbarton
Copy link
Contributor

I will work on semantic-release...after I get it to work on the karma-runner/karma project.

@franktopel
Copy link
Contributor

I think this can be closed as of release 2.0.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants