-
Notifications
You must be signed in to change notification settings - Fork 127
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade mkdirp 0.5.1 -> 0.5.3 to resolve minimist vulnerability #86
Comments
|
@mnepita : plenty of discussion in #85. We're basically waiting on the repo owner (not me) to execute & deploy the pull request. In the meantime, I'm going to try vuejs/vue-cli#5285 (comment) and report back here, #85 and / or stack overflow. |
Same here, please update asap
|
As suggested by @SakiiCode, I used https://www.npmjs.com/package/npm-force-resolutions as a temporary fix. I documented on SO at https://stackoverflow.com/a/60795003/1611925 and https://stackoverflow.com/a/60794976/1611925 . It installed without difficulty but I have not tested execution yet. |
Bump. |
cc @malept |
Owner of this project is @maxogden |
Thanks for your patience in these uncertain times. I've released a version of |
The dependency mkdirp is pinned to 0.5.1. Mkdirp 0.5.1 has its own pinned dependency, minimist 0.0.8, which has a vulnerability. extract-zip should be upgraded to use mkdirp 0.5.3 which uses a newer version of minimist.
See isaacs/node-mkdirp#7
The text was updated successfully, but these errors were encountered: