Skip to content
This repository has been archived by the owner on May 8, 2024. It is now read-only.

Fix severe vulnuerability - malicious package flatmap-sream removed #11

Closed
wants to merge 1 commit into from
Closed

Conversation

Cooper-Kunz
Copy link
Contributor

As I was filling out another issue (#10) outlining a version upgrade from Jade to Pug, I realized that this project's dependencies had not been updated in some time.

There is a well known vulnerability in the package flatmap-stream, which was a subdependency of nodemon up until version 1.18.7. You can review the conversation regarding updating it on GitHub here.

This pull request simply upgrades the nodemon package to the most recent version (1.18.7), which no longer uses the malicious package. All previous functionality remains intact.

Note that I'm also happy to submit an additional pr with my upgrade from #10, and any other needed packages.

@Cooper-Kunz
Copy link
Contributor Author

Closed due to committing package.lock unnecessarily. Will submit separate PR just updating package.json.

@Cooper-Kunz Cooper-Kunz closed this Dec 3, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant