-
Notifications
You must be signed in to change notification settings - Fork 536
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
NPM audit: critical vulnerability #282
Comments
Thanks for the PR -- I just merged it. For the record, the reported vulnerability did not apply to |
Thanks, happy to help! True that there were no real vulnerabilities, but since npm version 6 was released, |
npm audit
reports a critical vulnerability concerningopen
package. There seems to be no fix available inopen
, and it's not under active development anymore (last updated 4 years ago) and should be deprecated:pwnall/node-open#67
pwnall/node-open#68
There is an alternative (actively maintained) package available over here: https://www.npmjs.com/package/opn. A quick search shows that there is one line of code using the
open
package at the moment, and needs to be changed: https://github.com/mbloch/mapshaper/blob/master/bin/mapshaper-gui#L104The text was updated successfully, but these errors were encountered: