Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump diff to 4.* to resolve github warning #5

Closed
wants to merge 1 commit into from

Conversation

StoneCypher
Copy link
Contributor

I use documentation, which uses disparity, which uses diff from four years ago (1.3.2 vs 4.0.1 current)

An obscure bug is marked high severity (wrongly) on Github's warning system. Bumping diff fixes it with no code changes. Tests continue to pass.

Fixes #3

Caused by this

image

Thanks kindly

@StoneCypher
Copy link
Contributor Author

Also referenced as documentationjs/documentation#1257

@ruyadorno ruyadorno closed this in d479657 Nov 6, 2019
@StoneCypher
Copy link
Contributor Author

well that sucks, i don't get to be a contributor after all because someone else did it again six months later :(

@ruyadorno
Copy link
Collaborator

hi @StoneCypher I'm really really sorry you had to go through this 😞 it was totally not my intention - to make it clear the project seemed abandoned and I just asked Miller for access in order to at least fix the security issue #3 so that's why I rushed all fixes and pushed instead of merging community contributions. Looking back now that was definitely wrong.

I really believe in open source and the power of the community so I'm really sad to let down someone that put effort into participating like you did. I understand in case you can't forgive me but what I did in an effort to make up for this big mistake was to merge your commit into master in its current state, so that you'll get to be a contributor.

Many thanks for your contribution ❤️ and sorry again about all this.

@StoneCypher
Copy link
Contributor Author

i appreciate your helping me get my badge, friend :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security issue with old version of Diff dependency
2 participants