Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

timespan 2.3.0 vulnerability #2943

Closed
billsmith5 opened this issue Mar 1, 2018 · 2 comments
Closed

timespan 2.3.0 vulnerability #2943

billsmith5 opened this issue Mar 1, 2018 · 2 comments

Comments

@billsmith5
Copy link

billsmith5 commented Mar 1, 2018

Expected behaviour

Passes security scan

Actual behavior

Fails security scan, is block by company firewall

Environment Details

I am using Anular CLI project
My company scans all dependencies for vulnerabilities using SonarQube. timespan 2.3.0 was blocked, so my builds fails

  • Karma version (output of karma --version):
    -- karma@2.0.0 / -- log4js@2.5.2 / -- loggly@1.1.1 / -- timespan@2.3.0

Steps to reproduce the behavior

https://snyk.io/test/npm/karma/2.0.0?
.
Is there a fix for this?

@johnjbarton
Copy link
Contributor

The downstream bug:
indexzero/TimeSpan.js#10

@johnjbarton
Copy link
Contributor

fixed in 3.0, log4js updated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants