Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NSP check is reporting vulnerability on latest Webpack package. #6513

Closed
sneharghya opened this issue Feb 17, 2018 · 4 comments
Closed

NSP check is reporting vulnerability on latest Webpack package. #6513

sneharghya opened this issue Feb 17, 2018 · 4 comments

Comments

@sneharghya
Copy link

Do you want to request a feature or report a bug?

What is the current behavior?

If the current behavior is a bug, please provide the steps to reproduce.

What is the expected behavior?

If this is a feature request, what is motivation or use case for changing the behavior?

Please mention other relevant information such as the browser version, Node.js version, webpack version, and Operating System.

Just executed the nsp check command on my project and it is reporting a vulnerability on latest webpack package due to a downstream dependency on the module hoek.
Please refer the link from node security: https://nodesecurity.io/advisories/566

Path: webpack >> watchpack@1.4.0>>chokidar@1.7.0>>fsevents@1.1.3>>node-pre-gyp@0.6.39>>hawk>>hoek

@EugeneHlushko
Copy link
Member

EugeneHlushko commented Feb 19, 2018

I think chokidar at webpack/watchpack needs version bump, can submit a pr if that sounds good @sokra

@alexander-akait
Copy link
Member

@EugeneHlushko PR welcome

@alexander-akait
Copy link
Member

@webpack-bot move to webpack/watchpack

@webpack-bot
Copy link
Contributor

I've moved it to webpack/watchpack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants