Update packages containing vulnerabilities #60
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
minimist
mkdirp
Upgrade to the latest version which uses
minimist
with vulnerability fix.@connectis/diff-test-coverage
This package contains three coverage parsing packages that use an outdated version of
mocha
that contains the vulnerability. Those packages only usemocha
for testing and the author should have included it in dev dependencies. Fixed using npm resolution. Tested inrosetta
usingyalc
.commitizen
Using an outdated version of
minimist
. Fixed using npm resolution. Tested.Will remove when this issue is resolved:
commitizen/cz-cli#715
handlebars
Uses
optimist
which uses an outdated version ofminimist
. Fixed using npm resolution. Tested.Will remove when this issue is resolved:
handlebars-lang/handlebars.js#1658
acorn
jest
Reinstall to pull updated
acorn
dependency.