Vulnerable Dependency #603
Answered
by
ChristianMurphy
jasonchavez520
asked this question in
General
-
Remark Parse using old/vulnerable trim library. According to snyk, trim 0.0.1 is vulnerable to the following: https://snyk.io/vuln/SNYK-JS-TRIM-1017038 Can trim be updated to version 1.0.0? Thank you. |
Beta Was this translation helpful? Give feedback.
Answered by
ChristianMurphy
Jan 11, 2021
Replies: 1 comment
-
You may be on an old version or remark, or have locked trim in with a yarn.lock or package-lock.json file. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
ChristianMurphy
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
remark-parse
doesn't usetrim
, here is the current dependency tree.You may be on an o…