Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reported Vulnerability for package async/0.2.10 with ember cli 3.24.0 version #9896

Closed
amit199309 opened this issue May 9, 2022 · 2 comments

Comments

@amit199309
Copy link

amit199309 commented May 9, 2022

Hi Ember Cli Team,

I am using ember-cli 3.24, and this package using internally async/0.2.10 addon with path
( ember-cli/3.24.0 -> testem/3.6.0 -> fireworm/0.7.1 -> async/0.2.10 ) ,
During scan check this addon reported vulnerable and expecting latest version of this. So could you please work on this by update the package.json for ember-cli 3.24 to get the latest of async.

Please do needful.

Thank you

@amit199309 amit199309 changed the title Blackbuck reported Vulnerability for package async/0.2.10 with ember cli 3.24 version Blackbuck reported Vulnerability for package async/0.2.10 with ember cli 3.24.0 version May 9, 2022
@amit199309 amit199309 changed the title Blackbuck reported Vulnerability for package async/0.2.10 with ember cli 3.24.0 version Reported Vulnerability for package async/0.2.10 with ember cli 3.24.0 version May 9, 2022
@bertdeblock
Copy link
Contributor

ember-cli already depends on / allows the latest version of testem, so I'm not sure if there's anything we can do here. It seems that testem should get rid of fireworm in order to fix this. There's an open PR to address this: testem/testem#1482.

@bertdeblock
Copy link
Contributor

Going to close this one for now, for the reason mentioned above. Thanks for reporting!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants