Closed
Description
The c8 dependency istanbul-lib-report is causing a moderate security vulnerability finding. I've reported this directly on their repo: istanbuljs/istanbuljs#725 However, that repo was last updated in 2022, so I wanted to let you know too.
make-dir 2.0.0 - 3.1.0
Depends on vulnerable versions of semver
node_modules/make-dir
istanbul-lib-report >=2.0.5
Depends on vulnerable versions of make-dir
node_modules/istanbul-lib-report
c8 >=5.0.3
Depends on vulnerable versions of istanbul-lib-report
Depends on vulnerable versions of istanbul-reports
node_modules/c8
Root security finding: GHSA-c2qf-rxjj-qqgw
Please consider using an alternative library if they don't update their dependency. Thanks very much.
Metadata
Metadata
Assignees
Labels
No labels
Activity