-
Notifications
You must be signed in to change notification settings - Fork 147
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability in yargs-parser #725
Comments
Breaking changes don't look that bad, though I guess it can be hard to know for sure: https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md |
It's been AWHILE now. Any word on updating the vulnerable dependency? |
@fordN I haven't been paying close attention to gluegun for time constraint reasons, but now am back at it more regularly. I'll get a build pushed with yargs-parser updated today. |
yargs-parser 16.1.0 has a prototype pollution vulnerability: https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 This is fixed in 18.1.1 and later.
The text was updated successfully, but these errors were encountered: