Skip to content
This repository has been archived by the owner on Apr 24, 2023. It is now read-only.

Update dependencies to address security vulnerabilities present #13

Closed
wants to merge 1 commit into from

Conversation

SinS3i
Copy link

@SinS3i SinS3i commented Nov 26, 2018

flatmap-stream has been removed from registry, so it will fail install.
Another option is to pull in ^4.0.1 of event-stream instead of pinning at a lower version (3.3.4)

I would recommend not pulling in future versions until there is more details on how it happened / accountability from the publisher.

Related Issues Found:
dominictarr/event-stream#116
dominictarr/event-stream#115

@joaomoreno
Copy link
Owner

joaomoreno commented Nov 27, 2018

Sorry for not accepting this, I'd rather run the npm commands myself, since they produce changes in the package-lock.json file with integrity checks and package tarballs. I've pushed those changes myself and published a new version: 2.1.2. Thanks for calling out, though!

@joaomoreno joaomoreno closed this Nov 27, 2018
@SinS3i
Copy link
Author

SinS3i commented Nov 27, 2018

Totally understand, just wanted to give the option in case you were busy. Thanks for getting to it!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants