-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[4.x] High severity security issue in minimist
-dependency
#1841
Conversation
When doing a fresh install of
This PR will not solve those issues, since the lock-file is ignored when installing a package as dependency. Also the In our current |
Maybe we should use https://github.com/meszaros-lajos-gyorgy/minimist-lite instead of |
minimist
-dependency
indeed, i didn't notice that the update didn't upgrade minimist. |
Sorry, noticed this PR after I created #1843, however this PR seems to update in the 5.x-branch while mine updates in the 4.x. I'll close my PR if not applicable. |
updated dependencies according to npm audit fix.