Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update sass-graph to 3.0.5 to fix yargs-parser vulnerability #2921

Closed

Conversation

patomation
Copy link

Hello,

I wanted to update sass-graph to 3.0.5 the current version is 2.2.5.
This would update latest version of yargs-parser which will do away with the prototype vulnerability audit warnings.
As far as I can tell 2.2.6 was also released at the same time as 3.0.5 with the yargs updates. So maybe it's a better idea to update to just 2.2.6. But I still get a warning telling me to update to 3.0.5 when I tried it.

If it doesn't hurt anything maybe its not a bad idea to update to the latest version. Thoughts?

@xzyfer
Copy link
Contributor

xzyfer commented May 14, 2020

2.2.5 has the patched version of yargs.

@xzyfer xzyfer closed this May 14, 2020
@patomation
Copy link
Author

2.2.5 still has the warning

@patomation
Copy link
Author

Ah, I have other things that depend of a different version of yargs. My bad.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants