Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

config-store dependency needs updating #185

Closed
zenlex opened this issue Jul 31, 2020 · 2 comments
Closed

config-store dependency needs updating #185

zenlex opened this issue Jul 31, 2020 · 2 comments

Comments

@zenlex
Copy link

zenlex commented Jul 31, 2020

per https://npmjs.com/advisories/1213 dot-prop versions prior to 5.1.1 have a prototype pollution vulnerability. It has been patched >=5.1.1. config-store has been updated to the newer dot-prop version.

@zenlex zenlex changed the title dot-prop dependency needs updating config-store dependency needs updating Jul 31, 2020
@zenlex zenlex closed this as completed Jul 31, 2020
@chayev
Copy link

chayev commented Aug 3, 2020

Was this resolved? Or did you move this somewhere else? @zenlex

@zenlex
Copy link
Author

zenlex commented Aug 4, 2020

So I could be wrong - I’m fairly new to the whole package management /npm ecosystem....this was brought up by a security vulnerability thrown by the gatsby-cli related to dot-prop, update-notifier, configurable-store. When I tried to trace the problem there was an issue filed on one of the other packages that said the dependency issue landed here so I made the issue. When I took another look at the package.json file here though it looked like the version had already been updated to the recommended spec. That led me to think I had made an error in filing the issue so I closed it. If I’m correct it’s actually gatsby that now was behind on the update to the chain but again I’m new to this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants