Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch geojson-flatten version to pass npm audit #6

Open
vladkasianenko opened this issue Mar 16, 2021 · 0 comments
Open

Patch geojson-flatten version to pass npm audit #6

vladkasianenko opened this issue Mar 16, 2021 · 0 comments

Comments

@vladkasianenko
Copy link

vladkasianenko commented Mar 16, 2021

geojson-flatten uses old version of minimist what fails npm audit.

+-- @mapbox/mapbox-gl-draw@1.2.1
| +-- @mapbox/geojson-extent@0.3.2
| | `-- @mapbox/geojson-coords@0.0.0
| |   `-- geojson-flatten@0.2.4
| |     `-- minimist@1.2.0
| `-- @mapbox/geojsonhint@3.0.0
|   `-- minimist@1.2.0
  Low             Prototype Pollution                                           

  Package         minimist                                                      

  Patched in      >=0.2.1 <1.0.0 || >=1.2.3                                     

  Dependency of   @mapbox/mapbox-gl-draw [dev]                                  

  Path            @mapbox/mapbox-gl-draw > @mapbox/geojson-extent >             
                  @mapbox/geojson-coords > geojson-flatten > minimist           



  Low             Prototype Pollution                                           

  Package         minimist                                                      

  Patched in      >=0.2.1 <1.0.0 || >=1.2.3                                     

  Dependency of   @mapbox/mapbox-gl-draw [dev]                                  

  Path            @mapbox/mapbox-gl-draw > @mapbox/geojsonhint > minimist       

  More info       https://npmjs.com/advisories/1179  

Please, update version of geojson-flatten.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant