-
Notifications
You must be signed in to change notification settings - Fork 86
Open
Description
npm/yarn audit has started failing on this package because a vulnerability in the version of qs it depends on. Can you update it to a patched version?
C:\Users\pfaffle\git\tripwire\ui [master ≡]> yarn audit
yarn audit v1.22.0
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high │ Prototype Pollution Protection Bypass │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ qs │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=6.0.4 <6.1.0 || >=6.1.2 <6.2.0 || >=6.2.3 <6.3.0 || │
│ │ >=6.3.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ redux-api │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ redux-api > qs │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1469 │
└───────────────┴──────────────────────────────────────────────────────────────┘
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels