Skip to content
This repository has been archived by the owner on Jan 13, 2023. It is now read-only.

Commit

Permalink
fix(security): Bump npm-run-all version for security (#137)
Browse files Browse the repository at this point in the history
npm-run-all 4.1.3 depends indirectly on flatmap-stream, which has been yanked
from npm because it contained malicious code:

https://www.npmjs.com/advisories/737
mysticatea/npm-run-all#149
  • Loading branch information
bryanstearns authored and jamonholmgren committed Dec 27, 2018
1 parent ccfeb9a commit 54e4707
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion boilerplate/package.json.ejs
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@
"@types/validate.js": "0.11.0",
"babel-plugin-transform-inline-environment-variables": "0.4.3",
"jest-preset-ignite": "0.6.1",
"npm-run-all": "4.1.3",
"npm-run-all": "4.1.5",
"patch-package": "5.1.1",
"postinstall-prepare": "1.0.1",
"prettier": "1.12.1",
Expand Down

0 comments on commit 54e4707

Please sign in to comment.