Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High vulnerability | [email protected] #4331

Closed
4 tasks done
deleonio opened this issue Jun 12, 2020 · 0 comments · Fixed by #4333
Closed
4 tasks done

High vulnerability | [email protected] #4331

deleonio opened this issue Jun 12, 2020 · 0 comments · Fixed by #4333
Labels
area: security involving vulnerabilities

Comments

@deleonio
Copy link
Contributor

deleonio commented Jun 12, 2020

Prerequisites

  • Checked that your issue hasn't already been filed by cross-referencing issues with the faq label
  • Checked next-gen ES issues and syntax problems by using the same environment and/or transpiler configuration without Mocha to ensure it isn't just a feature that actually isn't supported in the environment in question or a bug in your code.
  • 'Smoke tested' the code to be tested by running it outside the real test suite to get a better sense of whether the problem is in the code under test, your usage of Mocha, or Mocha itself
  • Ensured that there is no discrepancy between the locally and globally installed versions of Mocha. You can find them with: node node_modules/.bin/mocha --version(Local) and mocha --version(Global). We recommend that you not install Mocha globally.

Description

The current mocha version contains a high vulnerability. That is a blocker for our CI/CD pipelines.

Steps to Reproduce

Findings: https://snyk.io/test/npm/mocha?tab=issues

Reproduces how often: always

Versions

  • The output of mocha --version and node node_modules/.bin/mocha --version:
  • The output of node --version:
  • Your operating system
    • name and version:
    • architecture (32 or 64-bit):
  • Your shell (e.g., bash, zsh, PowerShell, cmd):
  • Your browser and version (if running browser tests):
  • Any third-party Mocha-related modules (and their versions):
  • Any code transpiler (e.g., TypeScript, CoffeeScript, Babel) being used (and its version):

Additional Information

update to v3.1 - https://snyk.io/test/npm/serialize-javascript/3.1.0

@deleonio deleonio changed the title High vulnerabilty | [email protected] High vulnerability | [email protected] Jun 12, 2020
@boneskull boneskull added area: security involving vulnerabilities and removed unconfirmed-bug labels Jun 12, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area: security involving vulnerabilities
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants