Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

There is no 4.1.1 on npm #110

Closed
xPaw opened this issue Aug 17, 2020 · 8 comments
Closed

There is no 4.1.1 on npm #110

xPaw opened this issue Aug 17, 2020 · 8 comments

Comments

@xPaw
Copy link

xPaw commented Aug 17, 2020

warning mocha > yargs-unparser > [email protected]: Fixed a prototype pollution security issue in 4.1.0, please upgrade to ^4.1.1 or ^5.0.1.

But there is no 4.1.1 to update to. https://www.npmjs.com/package/flat/v/4.1.1

@DevRCRun
Copy link

Same is true of 4.1.2

@waldemarnt
Copy link

same here, any news?

@Hypnosphi
Copy link

@timoxley can you please comment on that?

@timoxley
Copy link
Contributor

timoxley commented Oct 14, 2020

Fixed. My bad, pushed tag to github but didn't publish to npm. 4.1.1 published + all other versions with previous prototype pollution fix.

Same is true of 4.1.2

There was never a 4.1.2.

@AviVahl
Copy link

AviVahl commented Oct 14, 2020

@timoxley latest now points to 3.0.1 instead of 5.0.2 :o

@timoxley
Copy link
Contributor

timoxley commented Oct 15, 2020

Ugh I thought npm fixed that so it wouldn't update the latest tag to an older version. Maybe I just dreamed that.

@timoxley
Copy link
Contributor

timoxley commented Oct 15, 2020

Will fix

@timoxley
Copy link
Contributor

Fixed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants