Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix(deps): force minimist >=1.2.6 for CVE-2021-44906
Ensures that yarn will only install 1.2.6 or newer versions for minimist. The proper fix would be to have the dependencies issue releases which upgrade their own (transitive) dependencies of minimist so that we don't have to explicitly force it here, but at the time of this writing these upgrades in our direct dependencies are just not available yet. Fixes #1943 Signed-off-by: Peter Somogyvari <[email protected]>
- Loading branch information