You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please upgrade dependencies to packages without known vulnerabilities.
This issues has been submitted to MSRC as vulnerability VULN-065752.
$ npm audit
# npm audit reportasync <2.6.4Severity: highPrototype Pollution in async - https://github.com/advisories/GHSA-fwr7-v2mv-hh25No fix availablenode_modules/asyncnode_modules/winston/node_modules/async tfx-cli * Depends on vulnerable versions of async Depends on vulnerable versions of prompt node_modules/tfx-cli winston 0.4.0 - 3.0.0-rc6 Depends on vulnerable versions of async node_modules/winston prompt >=0.1.8 Depends on vulnerable versions of winston node_modules/prompt4 high severity vulnerabilitiesSome issues need review, and may require choosinga different dependency.
$ npm list tfx-clikeptn-integration@1.0.0 /home/LOM0227/code/EMF.Keptn.Extension└── tfx-cli@0.11.0
The text was updated successfully, but these errors were encountered:
Please upgrade dependencies to packages without known vulnerabilities.
This issues has been submitted to MSRC as vulnerability VULN-065752.
The text was updated successfully, but these errors were encountered: