Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

yet another high severity vulnerability in the nested deps #2182

Closed
a-x- opened this issue Jul 10, 2019 · 2 comments
Closed

yet another high severity vulnerability in the nested deps #2182

a-x- opened this issue Jul 10, 2019 · 2 comments

Comments

@a-x-
Copy link

a-x- commented Jul 10, 2019

ava -> update-notifier -> ... -> deep-extend

CVE

Update please the update-notifier

Screenshot 2019-07-10 at 13 16 53

@novemberborn
Copy link
Member

Presumably however deep this dependency is installed, given that the fix is in a patch release it will be pulled in when you re-install your dependencies. But also, given that this is not a direct dependency of AVA, and not even a direct dependency of update-notifier, there is nothing we can do about this here. And finally, given that both AVA and update-notifier run during development rather than in your server, the kind of vulnerability described here simply will not affect you.

Assessing vulnerability reports is not easy, but there's no need to open these kinds of issues.

@a-x-
Copy link
Author

a-x- commented Jul 12, 2019

you can pin specific version into package-lock.json

the kind of vulnerability described here simply will not affect you

yes, I know it, i disabled this report

but there's no need to open these kinds of issues

hm, okaaaay...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants