Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump minimist from 1.2.5 to 1.2.6 #494

Closed
kiwi-cam opened this issue Jun 7, 2022 · 1 comment
Closed

Bump minimist from 1.2.5 to 1.2.6 #494

kiwi-cam opened this issue Jun 7, 2022 · 1 comment
Assignees
Labels
bug Something isn't working dependencies Pull requests that update a dependency file wontfix This will not be worked on

Comments

@kiwi-cam
Copy link
Owner

kiwi-cam commented Jun 7, 2022

│ Critical │ Prototype Pollution in minimist │
│ Package │ minimist │
│ Patched in │ >=1.2.6 │
│ Dependency of │ hap-nodejs [dev] │
│ Path │ hap-nodejs > @homebridge/dbus-native > optimist > minimist │
│ More info │ GHSA-xvch-5gv4-984h

│ Moderate │ Prototype Pollution in minimist │
│ Package │ minimist │
│ Patched in │ >=0.2.1 │
│ Dependency of │ hap-nodejs [dev] │
│ Path │ hap-nodejs > @homebridge/dbus-native > optimist > minimist │
│ More info │ GHSA-vh95-rmgr-6w4m

This dependency is coming from HAP-NodeJS. This issue is raised to bump these versions: homebridge/HAP-NodeJS#930

@kiwi-cam kiwi-cam added bug Something isn't working dependencies Pull requests that update a dependency file labels Jun 7, 2022
@kiwi-cam kiwi-cam self-assigned this Jun 7, 2022
@stale
Copy link

stale bot commented Sep 20, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Sep 20, 2022
@stale stale bot closed this as completed Oct 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working dependencies Pull requests that update a dependency file wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

1 participant