Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

minimist 1.2.5 has an active CVE #290

Closed
ckomali opened this issue Sep 18, 2024 · 2 comments
Closed

minimist 1.2.5 has an active CVE #290

ckomali opened this issue Sep 18, 2024 · 2 comments

Comments

@ckomali
Copy link

ckomali commented Sep 18, 2024

As per this https://nvd.nist.gov/vuln/detail/CVE-2021-44906 there is a known security issue. The issue is fixed in minimist 1.2.8 as per https://www.npmjs.com/package/minimist. Please update package.json and bump the version as required. It would be good to pick up the latest version 1.2.8.

@jgm jgm closed this as completed in cb7e2e3 Sep 19, 2024
@ckomali
Copy link
Author

ckomali commented Sep 19, 2024

Shouldn’t we bump commonmark version to 0.31.2 ?

@jgm
Copy link
Member

jgm commented Sep 19, 2024

ok I'll make a new release

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants