-
-
Notifications
You must be signed in to change notification settings - Fork 19
fix: update union-value #12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
this is no longer as annoying as it once was as seen in #13 but an upgrade would still be okay |
Indeed! Sorry for the late reply and thank you for the PR! I'll get this merged ASAP! |
|
Any progress on this change? We have some security vulnerabilities we would like to address and it appears that this may holding us up. |
|
@jonschlinkert also following up on this. We're getting security vulnerability notifications from the old version of |
|
hello? can we get this merged? |
|
@jonschlinkert would it be possible to get this merged? Many thanks, |
|
this package is probably no longer being maintained, last update was 2 years ago, |
|
This update isn't necessary due to the patches applied in the dependencies and the semver ranges used. If you're still getting security warnings from another tool you use, this guide might help ensure you have the latest versions. After that, if you're still receiving notices, there's probably incorrect information for version ranges specified for the security tool. We'll merge this PR when we have other changes to make in this library. |
|
I'm probably missing something here, but it seems to me that this PR would still be useful.
So it seems every published version of union-value still requires a set-value version which is triggering security tools. |
|
@thomasballinger |
avoid vulnerability from
cache-base > union-value > set-valuehttps://www.npmjs.com/advisories/1012