You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
snap-shot-it depends on snap-shot-core, which depends on mkdirp. Version 0.5.2 of mkdirp used to depend on minimist 0.0.8, which was recently marked as vulnerable by CVE-2020-7598. mkdirp 0.5.3 has recently been released to address the issue while maintaining backwards compatibility (mkdirp 1.x line has incompatible API).
Could you please update mkdirp to 0.5.3?
I also considered creating this issue in snap-shot-core's repo, but since I use snap-shot-it, I thought it would be better to post this here.
The text was updated successfully, but these errors were encountered:
pastelmind
changed the title
Update transitive dependency mkdirp 0.5.2
Update transitive dependency mkdirp to 0.5.3
Mar 18, 2020
snap-shot-it
depends onsnap-shot-core
, which depends onmkdirp
. Version 0.5.2 ofmkdirp
used to depend onminimist
0.0.8, which was recently marked as vulnerable by CVE-2020-7598.mkdirp
0.5.3 has recently been released to address the issue while maintaining backwards compatibility (mkdirp
1.x line has incompatible API).Could you please update
mkdirp
to 0.5.3?I also considered creating this issue in snap-shot-core's repo, but since I use snap-shot-it, I thought it would be better to post this here.
The text was updated successfully, but these errors were encountered: