Skip to content
This repository has been archived by the owner on Oct 3, 2023. It is now read-only.

Package dependencies contain a vulnerability in minimist #787

Closed
IdanAdar opened this issue Mar 28, 2020 · 1 comment · Fixed by #788
Closed

Package dependencies contain a vulnerability in minimist #787

IdanAdar opened this issue Mar 28, 2020 · 1 comment · Fixed by #788
Labels

Comments

@IdanAdar
Copy link

IdanAdar commented Mar 28, 2020

npm audit reveals the following:

Low           │ Prototype Pollution                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ minimist                                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=0.2.1 <1.0.0 || >=1.2.3                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ f39e5236885eb877c2528af825334df989f77901eab451dc3bf30ee73c6… │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ f39e5236885eb877c2528af825334df989f77901eab451dc3bf30ee73c6… │
│               │ >                                                            │
│               │ 119f77919637ddefbe3fb7c1f9e4251d45c468c0db7478b53eccb7ef05b… │
│               │ > @opencensus/nodejs > @opencensus/instrumentation-all >     │
│               │ @opencensus/instrumentation-grpc > grpc > node-pre-gyp >     │
│               │ mkdirp > minimist                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1179                            │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low           │ Prototype Pollution                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ minimist                                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=0.2.1 <1.0.0 || >=1.2.3                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ f39e5236885eb877c2528af825334df989f77901eab451dc3bf30ee73c6… │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ f39e5236885eb877c2528af825334df989f77901eab451dc3bf30ee73c6… │
│               │ >                                                            │
│               │ 119f77919637ddefbe3fb7c1f9e4251d45c468c0db7478b53eccb7ef05b… │
│               │ > @opencensus/nodejs > @opencensus/instrumentation-all >     │
│               │ @opencensus/instrumentation-grpc > grpc > node-pre-gyp > tar │
│               │ > mkdirp > minimist                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1179  
@mayurkale22
Copy link
Member

Thanks for reporting this. Please review #788

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants