Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch cacache to 10.0.4 (patches ssri to ^5.2.4) #236

Closed
EmilNordling opened this issue Mar 8, 2018 · 1 comment
Closed

Patch cacache to 10.0.4 (patches ssri to ^5.2.4) #236

EmilNordling opened this issue Mar 8, 2018 · 1 comment

Comments

@EmilNordling
Copy link

EmilNordling commented Mar 8, 2018

There's no harm that the know security vulnerability could do, the author specifies it here.

But ever since it's been reviewed, https://nvd.nist.gov/vuln/detail/CVE-2018-7651, as an know security vulnerability all repos that depends on this dependency gets a varning. Angular-cli is one of the bigger one that uses this dependency, and it's also quite common for whoever using Webpack.

The author of cacache seems to have fixed the vulnerability for cacache's 10.0.4 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants