Skip to content

Conversation

@jakejarvis
Copy link
Contributor

@jakejarvis jakejarvis commented Mar 18, 2020

yargs-parser v18.1.1 fixes a prototype pollution vulnerability:

? ✗ Medium severity vuln found in [email protected], introduced via [email protected]
    Description: Prototype Pollution
    Info: https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
    From: [email protected] > [email protected]

https://app.snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
yargs/yargs-parser#258

Thanks! 😊

@sindresorhus sindresorhus changed the title deps: Bump yargs-parser to v18.1.1 (fixes vulnerability) Update yargs-parser dependency Mar 19, 2020
@sindresorhus sindresorhus merged commit 4527b45 into sindresorhus:master Mar 19, 2020
@sindresorhus
Copy link
Owner

I'm merging this to silence the warning for people, but I strongly disagree that this is a vulnerability, and also, Snyk is not a trusted source: https://twitter.com/sindresorhus/status/1123986529498664961

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants