-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security vulnerability in dependency xml2js #6
Comments
@mattdesl Please take a look at this and update xml2js to 0.5.0. Thanks! |
@mattdesl |
Do we know when this update will happen @lorand-horvath @mattdesl ❓ |
@mattdesl doesn't seem to be responding at all. I've launched several requests in his direction, but haven't received any response yet. He is active on github though... his commits in May: https://github.com/mattdesl?tab=overview&from=2023-05-01&to=2023-05-31 |
@mattdesl plz look into it and merge pull request |
Fixed in #4 |
should be sorted now! |
This package depends on vulnerable versions of xml2js. xml2js should be updated to v0.5.0
From
npm audit
:The text was updated successfully, but these errors were encountered: