Skip to content
This repository has been archived by the owner on Sep 7, 2022. It is now read-only.

Dependency vulnerability #207

Open
metju90 opened this issue Oct 15, 2017 · 1 comment
Open

Dependency vulnerability #207

metju90 opened this issue Oct 15, 2017 · 1 comment

Comments

@metju90
Copy link

metju90 commented Oct 15, 2017

FYI you are using phantomjs-prebuilt which is using extract-zip@1.6.5 and extract-zip has a dependency debug@2.2.0 which is vulnerable. The latter is vulnerable itself and is also using a dependency ( ms@0.7.1 ) which has the same vulnerability.

Both vulnerable dependencies have fixed their issues but extract-zip latest version, 1.6.5 is still using the vulnerable versions.

More info: https://snyk.io/test/npm/karma-phantomjs-launcher

@radziksh
Copy link

radziksh commented Jan 3, 2019

@dignifiedquire JFYI I found some more vulnerabilities using the command yarn audit (we use yarn instead of npm):
screenshot_19
screenshot_20
screenshot_21
screenshot_22

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants