Skip to content
This repository has been archived by the owner on Nov 11, 2023. It is now read-only.

Security Vulnerability with dependency #351

Open
Aashu-stockgro opened this issue May 5, 2021 · 0 comments
Open

Security Vulnerability with dependency #351

Aashu-stockgro opened this issue May 5, 2021 · 0 comments

Comments

@Aashu-stockgro
Copy link

Describe the bug
A clear and concise description of what the bug is.
Hi,

Yargs parser has a prototype pollution vulnerability. I believe version 11 is being imported in restful-react thorugh a nested dependency. Can you please have a look.

https://snyk.io/vuln/npm:yargs-parser :- Highlights the safe versions

image

To Reproduce
Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior
A clear and concise description of what you expected to happen.

Screenshots
If applicable, add screenshots to help explain your problem.

Desktop (please complete the following information):

  • OS: [e.g. iOS]
  • Browser [e.g. chrome, safari]
  • Version [e.g. 22]

Smartphone (please complete the following information):

  • Device: [e.g. iPhone6]
  • OS: [e.g. iOS8.1]
  • Browser [e.g. stock browser, safari]
  • Version [e.g. 22]

Additional context
Add any other context about the problem here.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant