Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minimist dependency is causing Moderate-level security issue when running npm audit #29

Open
nnirror opened this issue Mar 18, 2020 · 0 comments

Comments

@nnirror
Copy link

nnirror commented Mar 18, 2020

The node-unzip-2 package has minimist as one of its dependencies. Minimist recently had a security vulnerability reported with NPM. Running npm audit on a project with node-unzip-2 installed returns the following:

Moderate Prototype Pollution
Package minimist
Patched in >=0.2.1 < 1.0.0 or >=1.2.3
Dependency of node-unzip-2
Path node-unzip-2 > fstream > mkdirp > minimist
More info https://nodesecurity.io/advisories/1179
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant