Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve minimist to 1.2.6 #7

Merged
merged 1 commit into from
Apr 13, 2022
Merged

Resolve minimist to 1.2.6 #7

merged 1 commit into from
Apr 13, 2022

Conversation

lachiet
Copy link
Contributor

@lachiet lachiet commented Apr 13, 2022

Fixes: https://github.com/coinbase/cbpay-js/security/dependabot/1

Motivation

Resolving security issue with lower versions of minimist.

@lachiet lachiet force-pushed the tweedie/minimist-appsec branch from 8cb515d to 3e2a913 Compare April 13, 2022 20:23
Copy link
Contributor

@gksander gksander left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NICE

@lachiet lachiet merged commit a254fa5 into master Apr 13, 2022
@lachiet lachiet deleted the tweedie/minimist-appsec branch April 13, 2022 20:24
@ljharb
Copy link
Contributor

ljharb commented Apr 14, 2022

Resolutions are both not needed here (because it's a semver range) and also should not be used in a published package (because consumers can't utilize them).

I'll share internally my guide to how to handle this sort of thing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants