Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependencies to pass audit #11

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

janlazo
Copy link

@janlazo janlazo commented Jun 13, 2019

                       === npm audit security report ===                        
                                                                                
# Run  npm install --save-dev @angular/compiler-cli@8.0.0  to resolve 1 vulnerability
SEMVER WARNING: Recommended action is a potentially breaking change
                                                                                
  Low             Regular Expression Denial of Service                          
                                                                                
  Package         braces                                                        
                                                                                
  Dependency of   @angular/compiler-cli [dev]                                   
                                                                                
  Path            @angular/compiler-cli > chokidar > anymatch > micromatch >    
                  braces                                                        
                                                                                
  More info       https://npmjs.com/advisories/786                              
                                                                                


                                                                                
                                 Manual Review                                  
             Some vulnerabilities require your attention to resolve             
                                                                                
          Visit https://go.npm.me/audit-guide for additional guidance           
                                                                                
                                                                                
  Moderate        Command Injection                                             
                                                                                
  Package         dot                                                           
                                                                                
  Patched in      No patch available                                            
                                                                                
  Dependency of   @compodoc/compodoc [dev]                                      
                                                                                
  Path            @compodoc/compodoc > @compodoc/ngd-transformer > dot          
                                                                                
  More info       https://npmjs.com/advisories/798                              
                                                                                
found 2 vulnerabilities (1 low, 1 moderate) in 15351 scanned packages
  1 vulnerability requires semver-major dependency updates.
  1 vulnerability requires manual review. See the full report for details.

@janlazo janlazo changed the title WIP: Bump dependencies to pass audit Bump dependencies to pass audit Jun 22, 2019
@janlazo
Copy link
Author

janlazo commented Jun 22, 2019

angular requires a release upgrade and olado/doT#242 remains open for dot. Nothing more can be done unless I upgrade devDependencies beyond the audit report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant