Skip to content

Security vulnerability in dependency #204

@pfaffle

Description

@pfaffle

npm/yarn audit has started failing on this package because a vulnerability in the version of qs it depends on. Can you update it to a patched version?

C:\Users\pfaffle\git\tripwire\ui [master ≡]> yarn audit
yarn audit v1.22.0
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high          │ Prototype Pollution Protection Bypass                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ qs                                                           │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=6.0.4 <6.1.0 || >=6.1.2 <6.2.0 || >=6.2.3 <6.3.0 ||        │
│               │ >=6.3.2                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ redux-api                                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ redux-api > qs                                               │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1469                        │
└───────────────┴──────────────────────────────────────────────────────────────┘

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions