Skip to content

Bump packages on vulnerability paths - #138

Merged
jackfranklin merged 1 commit into
jackfranklin:masterfrom
tombye:update-packages-with-vulnerabilities
May 30, 2019
Merged

jackfranklin merged 1 commit into
jackfranklin:masterfrom
tombye:update-packages-with-vulnerabilities

Conversation

@tombye

@tombye tombye commented Apr 5, 2019 •

Copy link
Copy Markdown
Contributor

Running npm audit on my project showed a few low-level vulnerabilities in the braces package, which is in the dependency tree of this project.

The braces package has this vulnerability:

https://nodesecurity.io/advisories/786

It's fixed as of version 2.3.1.

This updates all copies of the micromatch dependency in the tree to bring in a version of
braces with the fix.

The braces package has this vulnerability:

https://nodesecurity.io/advisories/786

It's fixed as of version 2.3.1.

This updates all copies of the micromatch
dependency in the tree to bring in a version of
braces with the fix.
@seahindeniz

Copy link
Copy Markdown

@jackfranklin please check this PR

@seahindeniz

Copy link
Copy Markdown

fixes #135

@gustawdaniel

Copy link
Copy Markdown

How to use this path if it is not merged?

@bung

bung commented May 23, 2019 •

Copy link
Copy Markdown

How to use this path if it is not merged?

npm install --save tombye/gulp-load-plugins#update-packages-with-vulnerabilities

@jackfranklin
jackfranklin merged commit 595ab83 into jackfranklin:master May 30, 2019
@jackfranklin

Copy link
Copy Markdown
Owner

This is published as 1.6.0. Apologies!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants