Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.
Sign upReported shelljs vulnerability through eslint@3.19.0 - use eslint@4.7.2 instead #995
Comments
This comment has been minimized.
This comment has been minimized.
tschoffelen
commented
Oct 4, 2017
|
Yes, I have the same problem, with us not really being able to use Any chance this dependency update will happen anytime soon? Cheers. Details here: https://www.bithound.io/github/standard/standard/master/dependencies/npm#filter-insecure-dep |
Flet
added
the
v11 release
label
Dec 15, 2017
This comment has been minimized.
This comment has been minimized.
|
Hi folks! A beta of the 11.0.0 version of standard has been released, which upgrades Could you give it a try? |
feross
added this to the
standard v11 milestone
Feb 17, 2018
This comment has been minimized.
This comment has been minimized.
|
Changelog: https://github.com/standard/standard/blob/master/CHANGELOG.md#1100---2018-02-18 |
bjedrzejewski commentedSep 29, 2017
I work in a high security environment and I wanted to use your library. Unfortunately it relies on eslint@3.19.0 that has a known shelljs vulnerability as reported here:
https://snyk.io/test/npm/standard?tab=issues
The good news is that the later version (4.7.2) of eslint does not have that vulnerability:
https://snyk.io/test/npm/eslint
Hopefully this is something that can be changed for this project.