Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot alerts #14

Closed
crivasestrada opened this issue Oct 6, 2021 · 2 comments · Fixed by #15
Closed

Dependabot alerts #14

crivasestrada opened this issue Oct 6, 2021 · 2 comments · Fixed by #15
Assignees

Comments

@crivasestrada
Copy link

Hi,
I would like to make a request about vulnerabilities detect in the security scan.
I have clone this repository and I haved passed a security scan. The Dependabot alerts show 3 vulnerabilities related to dependencies version included in the package-lock.json:

  • path-parse version 1.0.6 --> fixed vulnerability in version 1.0.7 or later
  • @actions/core version 1.2.1-->fixed vulnerability in version 1.2.6 or later
  • minimist version 0.0.8 --> fixed vulnerability in version 0.2.1 or later

Please, I would like to know if there is any plan to upgrade these dependencies version in orden to eliminate le vulnerabilities.

Thanks in advanced

@garrytrinder
Copy link
Member

Thank you @crivasestrada we will definitely look to resolve these vulnerabilities.

@garrytrinder
Copy link
Member

Thank you for raising this issue @crivasestrada 👍🏻

We have just released a new version, v2.0.1, that addresses these vulnerabilities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants