Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ps-tree version "1.1.0" has a deprecated dep due to malicious code #866

Closed
rg-najera opened this issue Dec 20, 2018 · 2 comments
Closed
Labels

Comments

@rg-najera
Copy link

rg-najera commented Dec 20, 2018

Bump ps-tree to >=1.1.1
Safe version has event stream locked to 3.3.4 https://github.com/indexzero/ps-tree/tree/1.1.1

More info on the threat
indexzero/ps-tree#33

Response from Yarn when trying to install deps

https://registry.yarnpkg.com/event-stream/-/event-stream-3.3.6.tgz: Request failed "404 Not Found"

Specifics on why its important:
dominictarr/event-stream#116

@jaredpalmer
Copy link
Owner

Can you submit a PR?

@stale stale bot added the stale label Feb 21, 2019
@fivethreeo
Copy link
Collaborator

fixed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants